
🚨 HIGH - OpenZiti controller enrollment privilege escalation (CVE-2026-58165) OpenZiti (ziti) through 2.0.0 has a privilege escalation flaw in the controller’s enrollment management path, allowing a non-admin identity to create enrollments for arbitrary identities, including the default administrator. The root cause is missing authorization / improper access control in the controller’s ApplyCreate function, which validates only that the target identity exists but not that the caller is permitted to act on it. An attacker with an identity that has enrollment management permissions can generate an enrollment for the admin identity, then redeem the one-time token via the unauthenticated enrollment endpoint to obtain an admin client certificate. Impact is full administrative takeover of the controller and complete control over the zero-trust overlay (policy manipulation, identity/service access changes, and broad compromise of managed connectivity). 👉 Affected: ziti (OpenZiti) <= 2.0.0 | Upgrade to No fix yet — treat as suspicious
Post summary
OpenZiti controllers up to version 2.0.0 contain a privilege escalation flaw that lets non-admin identities create admin enrollments, enabling full takeover of the controller. No patch is available yet.
