{"id":"GHSA-v859-c572-qh5p","summary":"ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions","details":"### Summary\n\nA bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between different organizations), **potentially** allowing users to keep access rights that were supposed to be completely removed.\n\n### Impact\n\nWhen an organization shares a project with another organization (a Project Grant), administrators can assign specific roles to users via a User Grant. If multiple roles are deleted from that project at the same time, a background process runs to strip those roles from the assigned users.\n\nBecause of an error in how ZITADEL loops through a user's list of roles during this specific cross-organization cleanup, deleting two or more roles at once **might** cause the system to accidentally skip over some of them.\n\n\u003e **Scope Note:** This vulnerability only affects **User Grants on Granted Projects**. Direct project roles and global organization roles are not impacted.\n\nThe risk depends entirely on what the skipped role allowed the user to do—if it was an administrative or high-privilege role, the user **could potentially** retain those elevated permissions within that granted project even after the role was officially deleted.\n\n### Affected Versions\n\n* **4.x:** `4.0.0` through `4.15.3` (including RC versions)\n* **3.x:** `3.0.0` through `3.4.12` (including RC versions)\n\nNote: The 3.x release channel has reached End-of-Life (EOL) for security updates and will not receive a backported patch.\n\n### Patches & Resolution\n\nThis issue has been fully resolved in the latest releases.\n\nThe update fixes the role-removal logic to ensure no roles are skipped. Furthermore, **this patch includes an automatic database migration**. When you update, the system will automatically scan your database, find any user permissions on granted projects that **may** have been accidentally left behind by this bug, and correct them.\n\n- **4.x**: Upgrade to $\\ge$[4.16.0](https://github.com/zitadel/zitadel/releases/tag/v4.16.0)\n- **3.x**: Update to $\\ge$[4.16.0](https://github.com/zitadel/zitadel/releases/tag/v4.16.0) (or check out workarounds)\n\n### Workarounds\n\nThere are no configuration workarounds. Upgrading to a patched version is the recommended solution and only way to trigger the automatic cleanup migration. If you cannot upgrade immediately, we recommend manually reviewing user permissions specifically for your **Granted Projects** where multiple roles were recently deleted.\n\n### Questions\n\nIf you have any questions or comments about this advisory, please reach out to us at security@zitadel.com.\n\n### Credits\n\nThanks to [AyushParkara](https://github.com/AyushParkara)  for reporting this vulnerability.","aliases":["CVE-2026-76081","GO-2026-6473"],"modified":"2026-09-17T17:40:58.977679639Z","published":"2026-09-14T21:31:37Z","database_specific":{"github_reviewed_at":"2026-09-14T21:31:37Z","nvd_published_at":null,"cwe_ids":["CWE-193"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-v859-c572-qh5p"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/commit/9d60e83d6faa5e7e7a5339e031cdb26e0efe4d59"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.16.0"}],"affected":[{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.16.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-v859-c572-qh5p/GHSA-v859-c572-qh5p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N"}]}