CVE-2026-58165
openziti ziti
OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attackers can redeem the resulting one-time token through the unauthenticated client API enrollment endpoint to obtain a c...
- CVSS
- 8.7
- EPSS
- 0.24% 15.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01