ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.
References
Configurations
No configuration.
History
10 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 17:16
Updated : 2026-07-10 19:17
NVD link : CVE-2026-55669
Mitre link : CVE-2026-55669
CVE.ORG link : CVE-2026-55669
JSON object : View
Products Affected
No product.
CWE
CWE-346
Origin Validation Error
