SCA: security update for github.com/zitadel/zitadel (GHSA-v859-c572-qh5p)

medium Tenable Cloud Security Plugin ID 447985

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL
updates permissions when multiple project roles are deleted at the same time can cause some user
permissions to be missed. This issue specifically affects User Grants on Granted Projects (projects shared
between different organizations), potentially allowing users to keep access rights that were supposed to
be completely removed. This issue has been fully resolved in version 4.16.0. There are no configuration
workarounds. Upgrading to a patched version is the only way to trigger the automatic cleanup migration.
Those who cannot upgrade immediately should manually review user permissions specifically for Granted
Projects where multiple roles were recently deleted. (CVE-2026-76081)

Solution

Update the github.com/zitadel/zitadel library and its related packages to version 4.16.0 or later.

See Also

https://github.com/advisories/GHSA-v859-c572-qh5p

Plugin Details

Severity: Medium

ID: 447985

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/15/2026

Updated: 9/15/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:C/A:N

CVSS Score Source: CVE-2026-76081

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/14/2026

Vulnerability Publication Date: 9/14/2026

Reference Information

CVE: CVE-2026-76081

cwe: CWE-193