Threat Advisory

ZITADEL JWT IdP Implementation Omits Token Expiration Validation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

ZITADEL is affected by four vulnerabilities involving JWT validation, account linking, OAuth2 token exchange authorization, and improper role revocation. The vulnerabilities affect multiple ZITADEL 3.x and 4.x releases, with severity ranging from Medium to High.

CVE-2026-56665 (CVSS 4.2 – Medium): A token lifecycle validation vulnerability in the external JWT Identity Provider allows JWTs without an exp claim to be accepted as valid indefinitely. An attacker possessing such a token could retain a permanent credential without an automatic expiration or revocation window.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

ZITADEL is affected by four vulnerabilities involving JWT validation, account linking, OAuth2 token exchange authorization, and improper role revocation. The vulnerabilities affect multiple ZITADEL 3.x and 4.x releases, with severity ranging from Medium to High.

CVE-2026-56665 (CVSS 4.2 – Medium): A token lifecycle validation vulnerability in the external JWT Identity Provider allows JWTs without an exp claim to be accepted as valid indefinitely. An attacker possessing such a token could retain a permanent credential without an automatic expiration or revocation window.[emaillocker id="1283"]

CVE-2026-56666 (CVSS 4.8 – Medium): An account-linking authorization flaw occurs when email auto-linking is enabled. ZITADEL verifies the local account's email but does not verify that the external IdP has also verified ownership of the email. An attacker could register an unverified account with a victim's email address on a permissive IdP and have it automatically linked to the victim's existing account.

CVE-2026-56668 (CVSS 8.1 – High): An authorization flaw in the OAuth2 Token Exchange endpoint allows an authenticated low-privileged user or client to exchange a token for one associated with a more privileged application. Missing audience ownership and scope validation can allow escalation to administrative project roles, access to sensitive profile information, or unauthorized access to other applications.

CVE-2026-76081 (CVSS 5.5 – Medium): An improper role revocation flaw can occur when multiple roles are deleted simultaneously from User Grants on Granted Projects. The cleanup process may skip some roles, allowing users to retain permissions that should have been removed, potentially including elevated project privileges.

RECOMMENDATION:

We recommend you to update zitadel to version 4.15.2 or later or 3.4.12 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu