Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55670

Опубликовано: 10 июл. 2026
Источник: nvd
EPSS Низкий

Описание

ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.

EPSS

Процентиль: 30%
0.00362
Низкий

Дефекты

CWE-284

Связанные уязвимости

github
3 месяца назад

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

EPSS

Процентиль: 30%
0.00362
Низкий

Дефекты

CWE-284