PT-2026-57256 · Zitadel · Zitadel

CVE-2026-56668

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions prior to 4.15.3
Description The OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange fails to verify if the subject token belongs to the requesting client or if the requested scopes are within the original token's scopes. This allows a token with low privileges to be exchanged for one with elevated permissions at another application.
Recommendations Update to version 4.15.3.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56668
GHSA-VRH8-C9CM-WH8V

Affected Products

Zitadel