CVE-2026-76081
### Summary A bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between different organizations), **potentially** allowing users to keep access rights that were supposed to be completely removed. ### Impact When an organization shares a project with another organization (a Project Grant), administrators can assign specific roles to users via a User Grant. If multiple roles are deleted from that project at the same time, a background process runs to strip those roles from the assigned users. Because of an error in how ZITADEL loops through a user's list of roles during this specific cross-organization cleanup, deleting two or more roles at once **might** cause the system to accidentally skip over some of them. > **Scope Note:** This vulnerability only affects **User Grants on Granted Projects**. Direct project roles and global organization roles are not impacted. The risk depends entirely on what the skipped role allowed the user to do—if it was an administrative or high-privilege role, the user **could potentially** retain those elevated permissions within that granted project even after the role was officially deleted. ### Affected Versions * **4.x:** `4.0.0` through `4.15.3` (including RC versions) * **3.x:** `3.0.0` through `3.4.12` (including RC versions) Note: The 3.x release channel has reached End-of-Life (EOL) for security updates and will not receive a backported patch. ### Patches & Resolution This issue has been fully resolved in the latest releases. The update fixes the role-removal logic to ensure no roles are skipped. Furthermore, **this patch includes an automatic database migration**. When you update, the system will automatically scan your database, find any user permissions on granted projects that **may** have been accidentally left behind by this bug, and corre
Properties
- ghsa_id
- GHSA-v859-c572-qh5p
- severity
- medium
- summary
- ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
- cvss_score
- 5.5
- cve_id
- CVE-2026-76081
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
- signal_observed_at
- 2026-09-14T23:09:48+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-14T21:31:37Z
- source_url
- https://github.com/advisories/GHSA-v859-c572-qh5p
- ghsa_updated
- 2026-09-14T21:31:38Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph