VYPR

Zitadel

by Zitadel

Source repositories

CVEs (58)

  • CVE-2025-64717CriNov 13, 2025
    risk 0.57cvss 9.8epss 0.00

    ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existing users in ZITADEL even if…

  • CVE-2025-64103CriOct 29, 2025
    risk 0.57cvss 9.8epss 0.00

    Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a user has set up MFA without this requirement, Zitadel would consider single factor auhtenticated…

  • CVE-2025-64102CriOct 29, 2025
    risk 0.57cvss 9.8epss 0.00

    Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While Zitadel allows preventing online brute force attacks in scenarios like TOTP, Email OTP, or…

  • CVE-2025-53895HigJul 15, 2025
    risk 0.57cvss 8.8epss 0.00

    ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a…

  • CVE-2023-46238HigOct 26, 2023
    risk 0.57cvss 8.7epss 0.00

    ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker…

  • CVE-2026-29191CriMar 7, 2026
    risk 0.53cvss 9.3epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

  • CVE-2025-67494CriDec 9, 2025
    risk 0.53cvss 9.3epss 0.00

    ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including…

  • CVE-2024-47000HigSep 20, 2024
    risk 0.53cvss 8.1epss 0.00

    Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the ability to request tokens, which could lead to unauthorized access to applications and…

  • CVE-2023-49097HigNov 30, 2023
    risk 0.53cvss 8.1epss 0.01

    ZITADEL is an identity infrastructure system. ZITADEL uses the notification triggering requests Forwarded or X-Forwarded-Host header to build the button link sent in emails for confirming a password reset with the emailed code. If this header is overwritten and a user clicks the…

  • CVE-2025-27507CriMar 4, 2025
    risk 0.52cvss 9.0epss 0.01

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specific IAM roles, to modify…

  • CVE-2026-32131HigMar 11, 2026
    risk 0.50cvss 7.7epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant.read, or project.app.read)…

  • CVE-2025-64431HigNov 7, 2025
    risk 0.50cvss epss 0.00

    Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and…

  • CVE-2024-29891HigMar 27, 2024
    risk 0.50cvss 8.7epss 0.01

    ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and pretend it is an image to gain access to the victim's account in certain scenarios. A possible victim would need to directly open the…

  • CVE-2022-36051HigAug 31, 2022
    risk 0.50cvss 8.7epss 0.01

    ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the API and **1.56.0** for Console, is a feature, where users with role.`ORG_OWNER` are able to create Javascript Code, which is invoked by the system at certain…

  • CVE-2026-32130HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.01

    ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with URL-encoded path values were…

  • CVE-2026-32132HigMar 11, 2026
    risk 0.48cvss 7.4epss 0.00

    ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the…

  • CVE-2024-46999HigSep 20, 2024
    risk 0.47cvss 7.3epss 0.00

    Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could lead to unauthorized access to applications and resources. Additionally, the management…

  • CVE-2026-54693HigJul 29, 2026
    risk 0.46cvss epss 0.00

    ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and…

  • CVE-2026-29193HigMar 7, 2026
    risk 0.46cvss 8.2epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were…

  • CVE-2026-29067HigMar 7, 2026
    risk 0.46cvss 8.1epss 0.00

    ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for…

Page 1 of 3