Security Advisory

CVE-2026-55669

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 16:58:46
Last updated 2026-07-10 18:16:52
Assigner GitHub_M
CVSS score 4.2
State PUBLISHED

Description

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.