HIGH 8.1 GitHub
CVE-2026-56668
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
### Summary
A vulnerability in ZITADEL’s OAuth2 Token Exchange endpoint allows an authenticated user or client to exchange a low-privilege access token for a token with elevated permissions at a completely different application. This bypasses the intended authorization and separation policies configured within ZITADEL.
### Impact
ZITADEL enables administrators to restrict token issuance based on client permissions, project roles, and specific scopes. Due to a missing verification step during
Affected Products
- go/github.com/zitadel/zitadel < 4.15.3
References
- https://github.com/advisories/GHSA-vrh8-c9cm-wh8v
- https://github.com/zitadel/zitadel/security/advisories/GHSA-vrh8-c9cm-wh8v
- https://nvd.nist.gov/vuln/detail/CVE-2026-56668
- https://github.com/zitadel/zitadel/commit/e2886a61670ca8fd41c9434f87036546e5620bcc
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-09-14 via GitHub. Affected: go/github.com/zitadel/zitadel < 4.15.3.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.