THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v859-c572-qh5p (medium) — ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

[GHSA] GHSA-v859-c572-qh5p (medium) — ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

medgithub_advisoriesPublished 2026-09-14

GHSA-v859-c572-qh5p Severity: medium CVE: CVE-2026-76081

ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions

### Summary

A bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between differ

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v859-c572-qh5p