zitadel

13 known vulnerabilities in zitadel, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-105215 CVSS 9.3 critical ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not…
  • CVE-2026-105214 CVSS 2.3 low Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal…
  • CVE-2026-105213 CVSS 8.8 high ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual…
  • CVE-2026-105212 CVSS 8.7 high ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts…
  • CVE-2026-105211 CVSS 9.2 critical ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over…
  • CVE-2026-105210 CVSS 8.8 high ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor…
  • CVE-2026-105209 CVSS 9.3 critical ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless…
  • CVE-2026-105208 CVSS 8.7 high ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing…
  • CVE-2026-105207 CVSS 9.3 critical ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying…
  • CVE-2026-105206 CVSS 5.3 medium ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies…
  • CVE-2026-85057 CVSS 8.7 high ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja…
  • CVE-2026-85056 CVSS 8.2 high ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password…
  • CVE-2026-76081 CVSS 5.5 medium ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple…