SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-55670

LOW · CVSS 2.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The vulnerability in ZITADEL's event store allows for the retention of the original resource owner associated with a deleted user identifier, potentially leading to unauthorized access for a newly recreated user under a different organization. This could expose sensitive information to the original organization's administrator, posing a significant risk to user privacy and data integrity. Organizations using ZITADEL versions prior to 4.15.2 should prioritize updating to mitigate this security concern.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55670
Severity
LOW
CVSS
2.3
EPSS
0.29%

Original NVD Description

ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.