← Späť na vyhľadávanie CVE

CVE-2026-55669

ZITADEL

Popis

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL-s external JWT Identity Provider validates a token-s signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.

CVSS 4.2EPSS 0.11199999999999999%Riziko 0.42
Zobraziť zdroj
Zverejnené
2026-07-10 17:16:59
Dotknuté verzie
<3.4.12, <4.15.2
Typ
Kritický softvér
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N