Executive brief
ZITADEL is an open-source identity management platform used to manage user authentication and access. A security flaw in its external identity provider integration allows a user with a valid login for one service to potentially gain unauthorized access to ZITADEL if both services use the same trusted identity provider. This could lead to unauthorized account access in specific enterprise environments where multiple applications share a single login provider.
Technical details
An authentication bypass vulnerability exists in ZITADEL's external JWT Identity Provider (IdP) implementation due to improper validation of the 'aud' (audience) claim. While ZITADEL correctly verifies the cryptographic signature and 'iss' (issuer) claim of incoming JSON Web Tokens, it does not check if the token was specifically intended for ZITADEL. An attacker with a valid token issued by a shared, trusted IdP for a different application can present that token to ZITADEL to authenticate. This requires the attacker to already possess a valid session from the shared issuer (PR:L) and depends on specific cross-service trust configurations (AC:H). The issue is resolved in versions 3.4.12 and 4.15.2 by enforcing audience validation.
Affected products
- ZITADEL ZITADEL >= 4.0.0, < 4.15.2; < 3.4.12
Timeline
- 2026-06-17: patched: Versions 3.4.12 and 4.15.2 released
- 2026-06-17: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: NVD publication date