CVE-2026-27840 | Zitadel up to 2.71.19/3.4.6/4.10.x Access Token token_id authentication bypass by assumed-immutable data (GHSA-6mq3-xmgp-pjm5 / EUVD-2026-8789)
A vulnerability has been found in Zitadel up to 2.71.19/3.4.6/4.10.x and classified as problematic. Affected by this issue is some unknown functionality of the component Access Token Handler. Performing a manipulation of the argument token_id results in authentication bypass by assumed-immutable data.
This vulnerability is identified as CVE-2026-27840. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.