Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76081— ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

Quick assessment

Affected
zitadel zitadel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ZITADEL 是一个开源的身份管理平台。在 4.16.0 之前的版本中,ZITADEL 在同时删除多个项目角色时的权限更新机制存在缺陷,可能导致部分用户权限未被正确移除。该问题特别影响“授权项目”(即跨组织共享的项目)中的用户授权(User Grants),可能导致用户保留了本应被完全移除的访问权限。此问题已在 4.16.0 版本中完全修复。目前没有配置层面的临时解决方案,升级至已修复的版本是唯一能触发自动清理迁移的方法。对于暂时无法立即升级的用户,建议手动审查“授权项目”中最近删除了多个角色所涉及的用户权限。

CVSS 5.5 · Medium EPSS 0.23% · P13

Affected Version Matrix 1

VendorProduct Version RangeStatus
zitadel zitadel < 4.16.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76081

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Source: CVE Program / CVE List V5
Vulnerability Description
ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted Projects (projects shared between different organizations), potentially allowing users to keep access rights that were supposed to be completely removed. This issue has been fully resolved in version 4.16.0. There are no configuration workarounds. Upgrading to a patched version is the only way to trigger the automatic cleanup migration. Those who cannot upgrade immediately should manually review user permissions specifically for Granted Projects where multiple roles were recently deleted.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
Off-by-one错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zitadel zitadel < 4.16.0 -

II. Public POCs for CVE-2026-76081

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76081

登录查看更多情报信息。

Patches & Fixes for CVE-2026-76081 (1)

Vendor Advisories for CVE-2026-76081 (1)

Vendor Pages for CVE-2026-76081 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76081

No comments yet


Leave a comment