HIGH 8.1 GitHub

CVE-2026-56668

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

### Summary A vulnerability in ZITADEL’s OAuth2 Token Exchange endpoint allows an authenticated user or client to exchange a low-privilege access token for a token with elevated permissions at a completely different application. This bypasses the intended authorization and separation policies configured within ZITADEL. ### Impact ZITADEL enables administrators to restrict token issuance based on client permissions, project roles, and specific scopes. Due to a missing verification step during

Affected Products

References

Published: 2026-09-14 · Source: GitHub · Feed updated: 2026-09-15
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-09-14 via GitHub. Affected: go/github.com/zitadel/zitadel < 4.15.3.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.