{"id":"CVE-2024-47000","aliases":["GHSA-qr2h-7pwm-h393","GO-2024-3139"],"url":"https://o3.security/vulnerability/CVE-2024-47000","summary":"Service Users Deactivation not Working in Zitadel","details":"### Impact\nZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and resources.\n\n### Patches\n\n2.x versions are fixed on >= [2.62.1](https://github.com/zitadel/zitadel/releases/tag/v2.62.1)\n2.61.x versions are fixed on >= [2.61.1](https://github.com/zitadel/zitadel/releases/tag/v2.61.1)\n2.60.x versions are fixed on >= [2.60.2](https://github.com/zitadel/zitadel/releases/tag/v2.60.2)\n2.59.x versions are fixed on >= [2.59.3](https://github.com/zitadel/zitadel/releases/tag/v2.59.3)\n2.58.x versions are fixed on >= [2.58.5](https://github.com/zitadel/zitadel/releases/tag/v2.58.5)\n2.57.x versions are fixed on >= [2.57.5](https://github.com/zitadel/zitadel/releases/tag/v2.57.5)\n2.56.x versions are fixed on >= [2.56.6](https://github.com/zitadel/zitadel/releases/tag/v2.56.6)\n2.55.x versions are fixed on >= [2.55.8](https://github.com/zitadel/zitadel/releases/tag/v2.55.8)\n2.54.x versions are fixed on >= [2.54.10](https://github.com/zitadel/zitadel/releases/tag/v2.54.10)\n\n### Workarounds\nInstead of deactivating the service account, consider creating new credentials and replacing the old ones wherever they are used. This effectively prevents the deactivated service account from being utilized.\n\n- Revoke all existing authentication keys associated with the service account\n- Rotate the service account's password\n\n### Questions\nIf you have any questions or comments about this advisory, please email us at \n\n[security@zitadel.com](mailto:security@zitadel.com)","published":"2024-09-19T23:10:33.882Z","modified":"2026-08-12T03:51:45.362858120Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.62.1"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.61.1"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.60.2"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.59.3"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.58.5"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.57.5"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.56.6"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.55.8"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel/v2","fixedVersion":"2.54.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47000.json"},{"type":"ADVISORY","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-qr2h-7pwm-h393"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47000"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.362858120Z"}}