CVE-2026-56668: Privilege Escalation and Cross-Client Audience Bypass in ZITADEL OAuth2 Token Exchange
Vulnerability ID: CVE-2026-56668
CVSS Score: 8.1
Published: 2026-09-14
A security vulnerability in ZITADEL's backend implementation of the OAuth2 Token Exchange endpoint allows authenticated clients to perform scope escalation and cross-client audience bypass. Prior to version 4.15.3, the Token Exchange flow lacked crucial validation logic, enabling low-privilege tokens to be exchanged for high-privilege tokens or tokens valid within other client applications, violating the OAuth2 delegation model.
TL;DR
ZITADEL prior to v4.15.3 fails to validate that a subject token belongs to the requesting client or client project, and fails to ensure requested scopes are a subset of the original token scopes. This allows attackers to escalate privileges or bypass cross-client audience boundaries.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862
- Attack Vector: Network
- CVSS Score: 8.1
- EPSS Score: 0.00413 (Percentile: 34.75%)
- Impact: Privilege Escalation & Audience Bypass
- Exploit Status: Proof of Concept available in tests
- KEV Status: Not listed
Affected Systems
- ZITADEL OIDC backend package (OAuth2 Token Exchange Flow)
-
ZITADEL: < 4.15.3 (Fixed in:
4.15.3)
Code Analysis
Commit: e2886a6
Fix OAuth2 Token Exchange scope validation and audience verification
Mitigation Strategies
- Upgrade ZITADEL deployments to version 4.15.3 or higher immediately.
- Review historical logs for suspicious token exchange requests involving mismatched client IDs and escalated scopes.
Remediation Steps:
- Identify all running instances of ZITADEL in the environment.
- Update the container images or binaries to version 4.15.3.
- Verify the deployment by executing a test token exchange with an invalid scope to ensure it is rejected with an invalid_scope error.
- Monitor authorization server logs for the specific error codes OIDC-zi9Y0 and invalid_scope.
References
Read the full report for CVE-2026-56668 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)