CVE-2026-54693
- EPSS 0.34%
- Veröffentlicht 29.07.2026 16:50:39
- Zuletzt bearbeitet 30.07.2026 20:07:01
ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_ph...
CVE-2026-56668
- EPSS 0.23%
- Veröffentlicht 10.07.2026 17:46:25
- Zuletzt bearbeitet 14.07.2026 14:16:35
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requ...
CVE-2026-56666
- EPSS 0.19%
- Veröffentlicht 10.07.2026 17:37:37
- Zuletzt bearbeitet 13.07.2026 19:17:23
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email befor...
CVE-2026-56667
- EPSS 0.23%
- Veröffentlicht 10.07.2026 17:25:46
- Zuletzt bearbeitet 10.07.2026 21:16:57
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an or...
CVE-2026-56665
- EPSS 0.17%
- Veröffentlicht 10.07.2026 17:22:46
- Zuletzt bearbeitet 10.07.2026 19:17:26
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider va...
CVE-2026-56664
- EPSS 0.2%
- Veröffentlicht 10.07.2026 17:21:22
- Zuletzt bearbeitet 10.07.2026 19:17:26
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits ...
CVE-2026-55672
- EPSS 0.28%
- Veröffentlicht 10.07.2026 17:19:05
- Zuletzt bearbeitet 10.07.2026 19:17:25
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authoriza...
CVE-2026-55671
- EPSS 0.25%
- Veröffentlicht 10.07.2026 17:17:50
- Zuletzt bearbeitet 14.07.2026 02:16:56
ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches do not consistently validate user-defined URLs against protected deny...
CVE-2026-55669
- EPSS 0.11%
- Veröffentlicht 10.07.2026 17:16:59
- Zuletzt bearbeitet 10.07.2026 19:17:25
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trust...
CVE-2026-55670
- EPSS 0.29%
- Veröffentlicht 10.07.2026 17:15:44
- Zuletzt bearbeitet 10.07.2026 21:16:56
ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organiz...