THREAT OPS › Threat News › [GHSA] GHSA-v859-c572-qh5p (medium) — ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
[GHSA] GHSA-v859-c572-qh5p (medium) — ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
GHSA-v859-c572-qh5p Severity: medium CVE: CVE-2026-76081
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
### Summary
A bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between differ
Indicators of compromise
- CVE-2026-76081cve
- security@zitadel.comemail
Original source: https://github.com/advisories/GHSA-v859-c572-qh5p