Impact
ZITADEL is an open source identity‑management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This authorisation failure (CWE‑284) and incomplete authorisation logic (CWE‑639) allows administrators of one tenant to view data belonging to another tenant, compromising confidentiality across tenant boundaries. The issue is fixed in version 4.15.2.
Affected Systems
ZITADEL, the open‑source identity‑management platform, for all released versions prior to 4.15.1. The issue is fixed from version 4.15.2 onward.
Risk and Exploitability
The CVSS score of 2.3 denotes a low severity rating, and the EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is based on the ability of an attacker to create or register a new account with a reused identifier; this inference is drawn from the description of the flaw. Because the flaw leaks data across tenant boundaries, a single compromised or misconfigured user can expose data to an unauthorized tenant administrator, though the overall risk remains limited by the low CVSS and EPSS scores.
OpenCVE Enrichment
Github GHSA