zitadel has 15 CVEs on record between 2023 and 2026. Cadence is steady at roughly 5 per quarter. The busiest recent month was June 2026 with 6. The median CVSS is 5.7 (medium). None have a confirmed exploitation report. Most affected products: github.com/zitadel/zitadel (13), zitadel (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.7
- Publish → KEV
- —
- Last 90 days
- 5 prev 6
Products
- github.com/zitadel/zitadel 13
- zitadel 2
Worst active — by depth score
CVE-2026-56668High· 8.1ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange45CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection45CVE-2026-54693HighZITADEL Users Can Self-Verify Email/Phone via API41CVE-2026-55672High· 7.4 ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)41CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution40
zitadel vulnerabilities
CVEs affecting zitadel, newest first. Open any entry for full detail, references, and exploit status.
15 CVEsRSS
CVE-2026-56668High· 8.1ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
CVE-2026-76081Medium· 5.5ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…
CVE-2026-56665Medium· 4.2ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
CVE-2026-54693HighZITADEL Users Can Self-Verify Email/Phone via API
ZITADEL Users Can Self-Verify Email/Phone via API
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the sam…
CVE-2026-56664Medium· 4.2ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-55671LowZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
CVE-2026-55670LowZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
CVE-2026-55672High· 7.4ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
GHSA-wxg7-w2v3-w38gMedium· 4.2ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
CVE-2026-55669Medium· 4.2ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
CVE-2024-32868Medium· 6.5ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount…
CVE-2023-49097High· 8.1ZITADEL Account Takeover via Malicious Host Header Injection
ZITADEL Account Takeover via Malicious Host Header Injection
CVE-2023-47111High· 7.3ZITADEL race condition in lockout policy execution
ZITADEL race condition in lockout policy execution
CVE-2023-22492Medium· 5.9Zitadel RefreshToken invalidation vulnerability
Zitadel RefreshToken invalidation vulnerability