PT-2026-91738 · Zitadel · Zitadel
CVE-2026-76081
·
Published
2026-09-14
·
Updated
2026-09-21
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.0.0 through 4.15.3
ZITADEL versions 3.0.0 through 3.4.12
Description
A bug exists in how the platform updates permissions when multiple project roles are deleted simultaneously. This issue specifically affects User Grants on Granted Projects, which are projects shared between different organizations. Due to an error in the logic used to loop through a user's list of roles during cross-organization cleanup, the system may skip certain roles, potentially allowing users to retain access rights and elevated permissions that should have been removed.
Recommendations
Upgrade to version 4.16.0 or later to fix the role-removal logic and trigger an automatic database migration to correct missed permissions.
Manually review user permissions for Granted Projects where multiple roles were recently deleted if an immediate upgrade is not possible.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel