CVE-2026-27840Disclosure(zitadel / zitadel)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format truncated to 80 characters are still considered valid. Zitadel uses a symmetric AES encryption for opaque tokens. The cleartext payload is a concatenation of a couple of identifiers, such as a token ID and user ID. Internally Zitadel has 2 different versions of token payloads. v1 tokens are no longer created, but are still verified as to not invalidate existing session after upgrade. The cleartext payload has a format of `<token_id>:<user_id>`. v2 tokens distinguished further where the `token_id` is of the format `v2_<oidc_session_id>-at_<access_token_id>`. V1 token authZ/N session data is retrieved from the database using the (simple) `token_id` value and `user_id` value. The `user_id` (called `subject` in some parts of our code) was used as being the trusted user ID. V2 token authZ/N session data is retrieved from the database using the `oidc_session_id` and `access_token_id` and in this case the `user_id` from the token is ignored and taken from the session data in the database. By truncating the token to 80 chars, the user_id is now missing from the cleartext of the v2 token. The back-end still accepts this for above reasons. This issue is not considered exploitable, but may look awkward when reproduced. The patch in versions 4.11.0 and 3.4.7 resolves the issue by verifying the `user_id` from the token against the session data from the database. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-302

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zitadel

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
zitadel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-26: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 102-2602-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27840: ZITADEL Opaque Token Validation Logic Flaw A logical integrity vulnerability exists in ZITADEL's handling of V2 opaque access tokens. Due to insufficient validation of the decrypted token payload, the system accepts truncated tokens th... https://cvereports.com/reports/CVE-2026-27840

    Post summary

    ZITADEL has a logical integrity flaw in opaque token validation that allows truncated tokens to be accepted; no PoC, exploit, patch, or active exploitation is reported.

    0000063
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27840 ZITADEL is an open source identity management platform. Starting in version 2.31.0 and prior to versions 3.4.7 and 4.11.0, opaque OIDC access tokens in the v2 format … https://www.cve.org/CVERecord?id=CVE-2026-27840

    Post summary

    The post announces CVE-2026-27840 affecting ZITADEL’s OIDC access tokens in specific versions, providing technical details but no PoC, exploit, or patch information.

    00000125
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzitadelzitadel---

Explore more