CVE-2026-56664: ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens from a trusted issuer to pass authentication. This issue is fixed in versions 3.4.12 and 4.15.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZITADELto a version that resolves this vulnerability.Fixed in 3.4.12 - Upgrade
Upgrade
ZITADELto a version that resolves this vulnerability.Fixed in 4.15.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56664?
CVE-2026-56664 has a medium severity rating of 4.2.
What does CVE-2026-56664 affect?
CVE-2026-56664 affects the ZITADEL open source identity management platform versions prior to 3.4.12 and 4.15.2.
What is the vulnerability in CVE-2026-56664?
CVE-2026-56664 involves missing JWT token lifecycle validation that allows the use of arbitrarily old tokens.
How do I fix CVE-2026-56664?
To mitigate CVE-2026-56664, upgrade ZITADEL to versions 3.4.12 or 4.15.2 or later.
What impact does CVE-2026-56664 have on security?
CVE-2026-56664 can potentially allow unauthorized access through the acceptance of outdated JWT tokens.