Vulnerability GO-2026-6473

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 days ago
September 16, 2026 at 04:56 PM UTC
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel
v0.0.0 - v1.87.5
v0.0.0 - v1.87.5

Summary

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel

Details

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/zitadel/zitadel before v4.16.0.

Timeline

Published
11 days ago
September 16, 2026 at 04:56 PM UTC
Last Modified
10 days ago
September 17, 2026 at 05:30 PM UTC