High severity8.1NVD Advisory· Published Jul 10, 2026· Updated Jul 14, 2026
CVE-2026-56668
CVE-2026-56668
Description
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested scopes remain within the original token's scopes, allowing a low-privilege token to be exchanged for elevated permissions at another application. This issue is fixed in version 4.15.3.
Affected products
1Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.