ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens from a trusted issuer to pass authentication. This issue is fixed in versions 3.4.12 and 4.15.2.
References
Configurations
No configuration.
History
10 Jul 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 18:16
Updated : 2026-07-10 19:17
NVD link : CVE-2026-56664
Mitre link : CVE-2026-56664
CVE.ORG link : CVE-2026-56664
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration
