7.4
CVE-2026-55672
- EPSS 0.28%
- Veröffentlicht 10.07.2026 17:19:05
- Zuletzt bearbeitet 10.07.2026 19:17:25
- CVE-Watchlists
- Unerledigt
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing intercepted grants or refresh tokens to be exchanged under a different client. This issue is fixed in versions 3.4.12 and 4.15.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerzitadel
≫
Produkt
zitadel
Version
>= 4.0.0-rc.1, < 4.15.2
Status
affected
Version
< 3.4.12
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.195 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/zitadel/zitadel/releases/tag/v3.4.12
https://github.com/zitadel/zitadel/releases/tag/v4.15.2
https://github.com/zitadel/zitadel/security/advisories/GHSA-xqxv-4jc2-x56x
https://github.com/zitadel/zitadel/commit/562403079a98cf2059cdac11865a45e2f285be71
https://github.com/zitadel/zitadel/commit/5b1708e0e650398f0ebc3341714f0798b0118917