Impact
Zitadel’s external JWT Identity Provider internally skips expiration validation when an incoming token omits the exp claim. Thus, a bearer token issued by a trusted external provider may be accepted without automatic expiration. Based on the description, it is inferred that an attacker could use or replay such a token without time‑bound constraints, potentially allowing prolonged unauthorized access.
Affected Systems
Zitadel identity platform releases prior to 3.4.12 (including the 3.0.0-rc.1 through 3.4.11 series) and prior to 4.15.2 (including the 4.0.0-rc.1 through 4.15.1 series) are vulnerable.
Risk and Exploitability
The CVSS score of 4.2 classifies the vulnerability as moderate. The EPSS score is below 1%, indicating a very low exploitation probability. Because the flaw is not in the CISA KEV catalog, no known widespread active exploits are reported. Based on the description, it is inferred that an attacker would need a valid or forged JWT and network access to the authentication flow, and no elevated server privileges are required.
OpenCVE Enrichment