CVE-2026-56667

HIGH CVSS 3.1: 7.3 EPSS 0.22%
Updated Jul 11, 2026
Zitadel
Parameter Value
CVSS 7.3 (HIGH)
Fixed In 4.15.3
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Zitadel
Public PoC No

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL Login V2 OIDC and SAML FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check, allowing an organization or instance administrator to store a javascript or data URI that can execute in a user's browser when an affected login error path is reached. This issue is fixed in version 4.15.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
High
Admin privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1