ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organization to be provisioned under the original organization and exposed to that organization's administrator. This issue is fixed in version 4.15.2.
https://github.com/zitadel/zitadel/security/advisories/GHSA-6x8v-2fq5-2229
https://github.com/zitadel/zitadel/releases/tag/v4.15.2
https://github.com/zitadel/zitadel/pull/12261
https://github.com/zitadel/zitadel/commit/a939b847d90c3370bd162064e57764b89c01be46
Published: 2026-07-10
Updated: 2026-07-10
Base Score: 6.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P
Severity: Medium
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 2.3
Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Severity: Low
EPSS: 0.00286