Impact
A bug in ZITADEL’s permission update logic causes incomplete revocation of user grants on projects shared between organizations when multiple role deletions are performed simultaneously. The flaw, classified as CWE‑193 (Off‑By‑One Error), can result in users retaining access rights that should have been fully removed, thereby elevating their privileges beyond what the current configuration authorizes.
Affected Systems
The issue affects installations of ZITADEL, specifically versions earlier than 4.16.0. The vulnerability manifests in the user grant mechanisms for granted projects shared across organizations, with no known configuration workarounds.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium likelihood of impact, while the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower exploitation probability in the broader threat landscape. The likely attack vector is internal: an actor with the ability to delete role assignments—such as an administrator or a malicious user who has gained similar privileges—could trigger the fault by deleting several roles at once, causing lingering permissions. No external exploit is required; the flaw is software‑logic based and requires authorized role‑deletion privileges.
OpenCVE Enrichment
Github GHSA