CPE
high
advisory
ZITADEL Privilege Escalation via OAuth2 Token Exchange
1 TTP 1 CVEA vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.
ZITADEL +1
auth-bypass
privilege-escalation
oauth2
1t
1c
low
advisory
Zitadel User API Verification Code Disclosure Vulnerability
1 TTP 1 CVEAn improper permission check in Zitadel's user API allows authenticated users to retrieve verification codes for arbitrary contact information, facilitating unauthorized verification of email addresses and phone numbers.
Zitadel 4.x +2
identity-management
auth-bypass
api-security
1t
1c