Zitadel

Zitadel

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 04.10.2026 13:10:07
  • Zuletzt bearbeitet 05.10.2026 14:17:18

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. U...

  • EPSS 0.22%
  • Veröffentlicht 04.10.2026 13:10:06
  • Zuletzt bearbeitet 05.10.2026 21:16:33

Zitadel before 4.16.2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of th...

  • EPSS 0.24%
  • Veröffentlicht 04.10.2026 13:10:05
  • Zuletzt bearbeitet 05.10.2026 16:17:11

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh t...

  • EPSS 0.32%
  • Veröffentlicht 04.10.2026 13:10:05
  • Zuletzt bearbeitet 05.10.2026 15:17:19

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. U...

  • EPSS 0.33%
  • Veröffentlicht 04.10.2026 13:10:04
  • Zuletzt bearbeitet 05.10.2026 15:17:19

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP...

  • EPSS 0.24%
  • Veröffentlicht 04.10.2026 13:10:03
  • Zuletzt bearbeitet 05.10.2026 14:17:18

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attack...

  • EPSS 0.22%
  • Veröffentlicht 04.10.2026 13:10:03
  • Zuletzt bearbeitet 05.10.2026 21:16:33

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization...

  • EPSS 0.31%
  • Veröffentlicht 04.10.2026 13:10:02
  • Zuletzt bearbeitet 06.10.2026 22:17:02

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Serv...

  • EPSS 0.08%
  • Veröffentlicht 04.10.2026 13:10:02
  • Zuletzt bearbeitet 05.10.2026 16:17:10

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacke...

  • EPSS 0.28%
  • Veröffentlicht 04.10.2026 13:10:01
  • Zuletzt bearbeitet 05.10.2026 15:17:18

ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated memb...