Description
ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted Projects (projects shared between different organizations), potentially allowing users to keep access rights that were supposed to be completely removed. This issue has been fully resolved in version 4.16.0. There are no configuration workarounds. Upgrading to a patched version is the only way to trigger the automatic cleanup migration. Those who cannot upgrade immediately should manually review user permissions specifically for Granted Projects where multiple roles were recently deleted.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via retained permissions
Action: Immediate Patch
AI Analysis

Impact

A bug in ZITADEL’s permission update logic causes incomplete revocation of user grants on projects shared between organizations when multiple role deletions are performed simultaneously. The flaw, classified as CWE‑193 (Off‑By‑One Error), can result in users retaining access rights that should have been fully removed, thereby elevating their privileges beyond what the current configuration authorizes.

Affected Systems

The issue affects installations of ZITADEL, specifically versions earlier than 4.16.0. The vulnerability manifests in the user grant mechanisms for granted projects shared across organizations, with no known configuration workarounds.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium likelihood of impact, while the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower exploitation probability in the broader threat landscape. The likely attack vector is internal: an actor with the ability to delete role assignments—such as an administrator or a malicious user who has gained similar privileges—could trigger the fault by deleting several roles at once, causing lingering permissions. No external exploit is required; the flaw is software‑logic based and requires authorized role‑deletion privileges.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to version 4.16.0 or later.
  • Manually audit and correct user permissions for granted projects that had multiple roles deleted recently.
  • Restrict role‑deletion operations to trusted administrators and audit role changes to prevent accidental or malicious retention of permissions.

Generated by OpenCVE AI on September 17, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v859-c572-qh5p ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Zitadel
Zitadel zitadel
Vendors & Products Zitadel
Zitadel zitadel

Mon, 14 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted Projects (projects shared between different organizations), potentially allowing users to keep access rights that were supposed to be completely removed. This issue has been fully resolved in version 4.16.0. There are no configuration workarounds. Upgrading to a patched version is the only way to trigger the automatic cleanup migration. Those who cannot upgrade immediately should manually review user permissions specifically for Granted Projects where multiple roles were recently deleted.
Title ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
Weaknesses CWE-193
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:21:51.412Z

Reserved: 2026-08-18T21:17:32.200Z

Link: CVE-2026-76081

cve-icon Vulnrichment

Updated: 2026-09-15T19:21:46.546Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T22:16:57.910

Modified: 2026-09-16T13:42:48.413

Link: CVE-2026-76081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses