Medium severity4.2NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-55669
CVE-2026-55669
Description
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted by ZITADEL. This issue is fixed in versions 3.4.12 and 4.15.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/zitadel/zitadelGo | < 1.80.0-v2.20.0.20260615132747-d184e976fc79 | 1.80.0-v2.20.0.20260615132747-d184e976fc79 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-g5h5-m4hm-xjrrghsaADVISORY
- github.com/zitadel/zitadel/commit/d184e976fc799a383bb6ef9f32c3bae11a3ef85fghsaWEB
- github.com/zitadel/zitadel/releases/tag/v3.4.12nvdWEB
- github.com/zitadel/zitadel/releases/tag/v4.15.2nvdWEB
- github.com/zitadel/zitadel/security/advisories/GHSA-g5h5-m4hm-xjrrnvdWEB
News mentions
0No linked articles in our index yet.