{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/zitadel-3.0.0-through-3.4.12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-56668"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZITADEL (3.0.0 through 3.4.12)","ZITADEL (4.0.0 through 4.15.2)"],"_cs_severities":["high"],"_cs_tags":["auth-bypass","privilege-escalation","oauth2"],"_cs_type":"advisory","_cs_vendors":["ZITADEL"],"content_html":"\u003cp\u003eZITADEL is vulnerable to an authorization flaw in its OAuth2 Token Exchange (RFC 8693) implementation, specifically within the \u003ccode\u003eurn:ietf:params:oauth:grant-type:token-exchange\u003c/code\u003e flow. The vulnerability (CVE-2026-56668) allows an authenticated user or client to exchange an existing low-privilege access token for a new token associated with a different, highly-privileged application.\u003c/p\u003e\n\u003cp\u003eThis occurs because the ZITADEL platform fails to verify if the subject of the incoming token is authorized to request the target audience or client. Furthermore, the system fails to enforce that the newly requested scopes are a subset of the original token's authorized scopes. An attacker can leverage this to acquire unauthorized project roles or access sensitive profile data across administrative boundaries. The risk is significantly amplified when public clients are involved, as they do not require client secrets to initiate the exchange. This vulnerability affects ZITADEL 3.x and 4.x versions prior to 4.15.3.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to escalate privileges from a low-privilege user to an administrative role within target projects or applications. This can lead to unauthorized data access, exfiltration of sensitive profile information, and complete control over secondary applications relying on ZITADEL for identity management. The vulnerability impacts all ZITADEL instances that allow OAuth2 Token Exchange, posing a critical risk to multi-tenant or project-based infrastructure where application-level isolation is enforced via ZITADEL.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade ZITADEL immediately to version 4.15.3 or later to resolve CVE-2026-56668.\u003c/li\u003e\n\u003cli\u003eIf patching is delayed, disable the Token Exchange functionality by setting \u003ccode\u003eZITADEL_DEFAULTINSTANCE_FEATURES_TOKENEXCHANGE=false\u003c/code\u003e via environment variables.\u003c/li\u003e\n\u003cli\u003eAlternatively, audit and remove the \u003ccode\u003eurn:ietf:params:oauth:grant-type:token-exchange\u003c/code\u003e grant type from all high-privilege or public client configurations within the ZITADEL console.\u003c/li\u003e\n\u003cli\u003eReview ZITADEL audit logs for anomalous token exchange requests where the requested client or scope appears inconsistent with the original token's assigned project context.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T07:04:14Z","date_published":"2026-09-15T07:04:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-auth-bypass/","summary":"A vulnerability in ZITADEL's OAuth2 Token Exchange endpoint (CVE-2026-56668) allows authenticated users to exchange low-privilege tokens for highly privileged tokens by bypassing authorization and scope validation checks.","title":"ZITADEL Privilege Escalation via OAuth2 Token Exchange","url":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - ZITADEL (3.0.0 Through 3.4.12)","version":"https://jsonfeed.org/version/1.1"}