CVE-2026-55672

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing intercepted grants or refresh tokens to be exchanged under a different client. This issue is fixed in versions 3.4.12 and 4.15.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-10 18:16

Updated : 2026-07-10 19:17


NVD link : CVE-2026-55672

Mitre link : CVE-2026-55672

CVE.ORG link : CVE-2026-55672


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-863

Incorrect Authorization