PT-2026-57252 · Zitadel · Zitadel

CVE-2026-56664

·

Published

2026-06-18

·

Updated

2026-07-10

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions prior to 3.4.12 ZITADEL versions prior to 4.15.2
Description External JWT Identity Provider validation in the internal/idp/providers/jwt/session.go file skips the maximum token age freshness check when an incoming token omits the iat claim. This allows arbitrarily old tokens from a trusted issuer to pass authentication.
Recommendations Update to version 3.4.12 or later. Update to version 4.15.2 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56664
GHSA-WXG7-W2V3-W38G
GO-2026-5732

Affected Products

Zitadel