CVE-2026-58165Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attackers can redeem the resulting one-time token through the unauthenticated client API enrollment endpoint to obtain a client certificate authenticating as the targeted admin identity, yielding full administrative control of the controller and the zero-trust overlay it manages.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - OpenZiti controller enrollment privilege escalation (CVE-2026-58165) OpenZiti (ziti) through 2.0.0 has a privilege escalation flaw in the controller’s enrollment management path, allowing a non-admin identity to create enrollments for arbitrary identities, including the default administrator. The root cause is missing authorization / improper access control in the controller’s ApplyCreate function, which validates only that the target identity exists but not that the caller is permitted to act on it. An attacker with an identity that has enrollment management permissions can generate an enrollment for the admin identity, then redeem the one-time token via the unauthenticated enrollment endpoint to obtain an admin client certificate. Impact is full administrative takeover of the controller and complete control over the zero-trust overlay (policy manipulation, identity/service access changes, and broad compromise of managed connectivity). 👉 Affected: ziti (OpenZiti) <= 2.0.0 | Upgrade to No fix yet — treat as suspicious

    Post summary

    OpenZiti controllers up to version 2.0.0 contain a privilege escalation flaw that lets non-admin identities create admin enrollments, enabling full takeover of the controller. No patch is available yet.

    0000096
    232 followersView on X

Explore more