CVE-2026-33132
- EPSS 0.09%
- Veröffentlicht 20.03.2026 10:21:19
- Zuletzt bearbeitet 23.03.2026 18:06:26
ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforcement during authentication. Zitadel allows applications to enforce an organzation context during auth...
CVE-2026-32132
- EPSS 0.04%
- Veröffentlicht 11.03.2026 21:40:07
- Zuletzt bearbeitet 16.03.2026 16:52:31
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An impr...
CVE-2026-32131
- EPSS 0.04%
- Veröffentlicht 11.03.2026 21:38:51
- Zuletzt bearbeitet 16.03.2026 16:52:22
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant...
CVE-2026-32130
- EPSS 0.24%
- Veröffentlicht 11.03.2026 21:37:07
- Zuletzt bearbeitet 16.03.2026 16:51:59
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with...
CVE-2026-29193
- EPSS 0.02%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 10.03.2026 17:52:35
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even ...
CVE-2026-29192
- EPSS 0.02%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 10.03.2026 17:54:28
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Default URI Redirect. This issue has been patched in ver...
CVE-2026-29191
- EPSS 0.02%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 10.03.2026 17:55:39
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched ...
CVE-2026-29067
- EPSS 0.01%
- Veröffentlicht 07.03.2026 15:15:54
- Zuletzt bearbeitet 10.03.2026 17:58:23
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requ...
CVE-2026-27946
- EPSS 0.04%
- Veröffentlicht 26.02.2026 00:34:56
- Zuletzt bearbeitet 05.03.2026 14:54:10
ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification p...
CVE-2026-27945
- EPSS 0.05%
- Veröffentlicht 26.02.2026 00:29:58
- Zuletzt bearbeitet 05.03.2026 16:04:24
ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such th...