ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation) (CVE-2026-55672)
Zitadel OAuth2/OIDC implementations in versions 3.0.0 through 3.4.11 and 4.0.0 through 4.15.1 omit client_id binding during authorization code exchange and refresh token flows, violating RFC 6749 Section 4.1.3. This allows an attacker who intercepts authorization codes or refresh tokens to use them with a different client identity, potentially gaining unauthorized access. Exploitation requires prior compromise or token theft in the application environment. PKCE mitigates some risks for authorization code injection but not refresh token misuse. The issue is fixed in versions 3.4.12 and 4.15.2 and later.
AI Analysis
Technical Summary
Zitadel's OAuth2/OIDC CodeExchange and RefreshToken flows fail to validate that the client requesting token exchange matches the client that initiated the authorization, violating RFC 6749 Section 4.1.3. This flaw enables attackers who have intercepted authorization codes or refresh tokens to exchange them under different client credentials, bypassing intended client boundaries. The vulnerability affects Zitadel versions 3.0.0 through 3.4.11 and 4.0.0 through 4.15.1. Exploitation requires an external vulnerability or data leak to obtain tokens. PKCE partially mitigates authorization code injection but not refresh token cross-use. The issue is resolved by reintroducing strict client identity validation in versions 3.4.12 and 4.15.2 and later.
Potential Impact
An attacker who intercepts an authorization code or refresh token can use it with a different client identity registered on the same Zitadel instance, potentially obtaining unauthorized access tokens for victim users. This breaks client isolation and can lead to unauthorized access across tenants in multi-tenant deployments. Exploitation requires prior compromise or token leakage outside Zitadel. PKCE mitigates some attack vectors but does not protect refresh token misuse. The vulnerability can lead to high confidentiality and integrity impact but does not affect availability.
Mitigation Recommendations
A fix is available. Upgrade Zitadel to version 3.4.12 or later for the 3.x series, or 4.15.2 or later for the 4.x series to restore strict client identity validation on authorization code and refresh token exchanges. Until patched, enforce PKCE for all clients to mitigate authorization code injection risks, minimize refresh token lifespans, and maintain strong application security to prevent token theft. No other workarounds fully address the vulnerability.
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation) (CVE-2026-55672)
Description
Zitadel OAuth2/OIDC implementations in versions 3.0.0 through 3.4.11 and 4.0.0 through 4.15.1 omit client_id binding during authorization code exchange and refresh token flows, violating RFC 6749 Section 4.1.3. This allows an attacker who intercepts authorization codes or refresh tokens to use them with a different client identity, potentially gaining unauthorized access. Exploitation requires prior compromise or token theft in the application environment. PKCE mitigates some risks for authorization code injection but not refresh token misuse. The issue is fixed in versions 3.4.12 and 4.15.2 and later.
CVSS v3.1
Score 7.4high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Zitadel's OAuth2/OIDC CodeExchange and RefreshToken flows fail to validate that the client requesting token exchange matches the client that initiated the authorization, violating RFC 6749 Section 4.1.3. This flaw enables attackers who have intercepted authorization codes or refresh tokens to exchange them under different client credentials, bypassing intended client boundaries. The vulnerability affects Zitadel versions 3.0.0 through 3.4.11 and 4.0.0 through 4.15.1. Exploitation requires an external vulnerability or data leak to obtain tokens. PKCE partially mitigates authorization code injection but not refresh token cross-use. The issue is resolved by reintroducing strict client identity validation in versions 3.4.12 and 4.15.2 and later.
Potential Impact
An attacker who intercepts an authorization code or refresh token can use it with a different client identity registered on the same Zitadel instance, potentially obtaining unauthorized access tokens for victim users. This breaks client isolation and can lead to unauthorized access across tenants in multi-tenant deployments. Exploitation requires prior compromise or token leakage outside Zitadel. PKCE mitigates some attack vectors but does not protect refresh token misuse. The vulnerability can lead to high confidentiality and integrity impact but does not affect availability.
Mitigation Recommendations
A fix is available. Upgrade Zitadel to version 3.4.12 or later for the 3.x series, or 4.15.2 or later for the 4.x series to restore strict client identity validation on authorization code and refresh token exchanges. Until patched, enforce PKCE for all clients to mitigate authorization code injection risks, minimize refresh token lifespans, and maintain strong application security to prevent token theft. No other workarounds fully address the vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xqxv-4jc2-x56x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55672"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a58b41668715ace43d68576
Added to database: 07/16/2026, 10:36:06 UTC
Last enriched: 07/16/2026, 10:57:29 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.