Vulnerability GO-2026-6474
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 days ago
September 16, 2026 at 04:56 PM UTC
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel
v0.0.0 - v1.87.5
v0.0.0 - v1.87.5
Summary
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel
Details
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange in github.com/zitadel/zitadel.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/zitadel/zitadel before v4.15.3.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 days ago
ZITADEL: MFA bypass via session reuse in Login V2
v0.0.0 - v1.80.0-v2.20 GHSA-9993-rfwp-rhwf
v0.0.0 - v1.80.0-v2.20 GHSA-9993-rfwp-rhwf
High Risk
3 days ago
ZITADEL: Actions V1 sandbox escape: host file read via require()
v0.0.0 - v1.80.0-v2.20 GHSA-fgmf-7rf8-m6vf
v0.0.0 - v1.80.0-v2.20 GHSA-fgmf-7rf8-m6vf
Unknown
11 days ago
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider in github.com/zitadel/zitadel
v0.0.0 - v1.87.5 GO-2026-6469
v0.0.0 - v1.87.5 GO-2026-6469
Unknown
11 days ago
ZITADEL: Auto-linking by email: IdP-side email verification is not checked in github.com/zitadel/zitadel
v0.0.0 - v1.87.5 GO-2026-6470
v0.0.0 - v1.87.5 GO-2026-6470
Unknown
11 days ago
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions in github.com/zitadel/zitadel
v0.0.0 - v1.87.5 GO-2026-6473
v0.0.0 - v1.87.5 GO-2026-6473
Impacted packages
Timeline
Published
11 days ago
September 16, 2026 at 04:56 PM UTC
Last Modified
10 days ago
September 17, 2026 at 05:30 PM UTC