PT-2026-91738 · Zitadel · Zitadel

CVE-2026-76081

·

Published

2026-09-14

·

Updated

2026-09-21

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.15.3 ZITADEL versions 3.0.0 through 3.4.12
Description A bug exists in how the platform updates permissions when multiple project roles are deleted simultaneously. This issue specifically affects User Grants on Granted Projects, which are projects shared between different organizations. Due to an error in the logic used to loop through a user's list of roles during cross-organization cleanup, the system may skip certain roles, potentially allowing users to retain access rights and elevated permissions that should have been removed.
Recommendations Upgrade to version 4.16.0 or later to fix the role-removal logic and trigger an automatic database migration to correct missed permissions. Manually review user permissions for Granted Projects where multiple roles were recently deleted if an immediate upgrade is not possible.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76081
GHSA-V859-C572-QH5P
GO-2026-6473
OPENSUSE-SU-2026:21897-1
SUSE-SU-2026:23855-1
SUSE-SU-2026:23863-1

Affected Products

Zitadel