CVE-2026-55670

ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jul 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 18:16

Updated : 2026-07-10 21:16


NVD link : CVE-2026-55670

Mitre link : CVE-2026-55670

CVE.ORG link : CVE-2026-55670


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-639

Authorization Bypass Through User-Controlled Key