mediumCVSS 5.5Vulnerability

CVE-2026-76081

### Summary A bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between different organizations), **potentially** allowing users to keep access rights that were supposed to be completely removed. ### Impact When an organization shares a project with another organization (a Project Grant), administrators can assign specific roles to users via a User Grant. If multiple roles are deleted from that project at the same time, a background process runs to strip those roles from the assigned users. Because of an error in how ZITADEL loops through a user's list of roles during this specific cross-organization cleanup, deleting two or more roles at once **might** cause the system to accidentally skip over some of them. > **Scope Note:** This vulnerability only affects **User Grants on Granted Projects**. Direct project roles and global organization roles are not impacted. The risk depends entirely on what the skipped role allowed the user to do—if it was an administrative or high-privilege role, the user **could potentially** retain those elevated permissions within that granted project even after the role was officially deleted. ### Affected Versions * **4.x:** `4.0.0` through `4.15.3` (including RC versions) * **3.x:** `3.0.0` through `3.4.12` (including RC versions) Note: The 3.x release channel has reached End-of-Life (EOL) for security updates and will not receive a backported patch. ### Patches & Resolution This issue has been fully resolved in the latest releases. The update fixes the role-removal logic to ensure no roles are skipped. Furthermore, **this patch includes an automatic database migration**. When you update, the system will automatically scan your database, find any user permissions on granted projects that **may** have been accidentally left behind by this bug, and corre

Properties

ghsa_id
GHSA-v859-c572-qh5p
severity
medium
summary
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
cvss_score
5.5
cve_id
CVE-2026-76081
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
signal_observed_at
2026-09-14T23:09:48+00:00
is_ghsa_only
false
ghsa_published
2026-09-14T21:31:37Z
source_url
https://github.com/advisories/GHSA-v859-c572-qh5p
ghsa_updated
2026-09-14T21:31:38Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/zitadel/zitadel

AFFECTS (1)

[Software]go/github.com/zitadel/zitadel

HAS_WEAKNESS (1)

[Weakness]Off-by-one Error

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph