CVE-2026-55669

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.
Configurations

No configuration.

History

10 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 17:16

Updated : 2026-07-10 19:17


NVD link : CVE-2026-55669

Mitre link : CVE-2026-55669

CVE.ORG link : CVE-2026-55669


JSON object : View

Products Affected

No product.

CWE
CWE-346

Origin Validation Error