NONE · 0

CVE-2026-55670

ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user rec...

Vulnerability Description

ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-55670?

CVE-2026-55670 is a documented vulnerability. ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user rec...

How severe is CVE-2026-55670?

CVSS scoring is not yet available for CVE-2026-55670. Check NVD for updates.

Is there a patch for CVE-2026-55670?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.