Low severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-55670
CVE-2026-55670
Description
ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/zitadel/zitadelGo | < 1.80.0-v2.20.0.20260615092437-6082e59d47c1 | 1.80.0-v2.20.0.20260615092437-6082e59d47c1 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-6x8v-2fq5-2229ghsaADVISORY
- github.com/zitadel/zitadel/commit/6082e59d47c17a9d54a6b0556b3f31559d7c620aghsaWEB
- github.com/zitadel/zitadel/releases/tag/v4.15.2nvdWEB
- github.com/zitadel/zitadel/security/advisories/GHSA-6x8v-2fq5-2229nvdWEB
- github.com/zitadel/zitadel/commit/a939b847d90c3370bd162064e57764b89c01be46nvd
- github.com/zitadel/zitadel/pull/12261nvd
News mentions
0No linked articles in our index yet.