CVE-2026-55671
- EPSS 0.25%
- Veröffentlicht 10.07.2026 17:17:50
- Zuletzt bearbeitet 14.07.2026 02:16:56
ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches do not consistently validate user-defined URLs against protected deny...
CVE-2026-55669
- EPSS 0.11%
- Veröffentlicht 10.07.2026 17:16:59
- Zuletzt bearbeitet 10.07.2026 19:17:25
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trust...
CVE-2026-55670
- EPSS 0.29%
- Veröffentlicht 10.07.2026 17:15:44
- Zuletzt bearbeitet 10.07.2026 21:16:56
ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the original resource owner for a deleted user identifier, causing a later user recreated with the same identifier in another organiz...
CVE-2026-44671
- EPSS 0.48%
- Veröffentlicht 14.05.2026 21:13:03
- Zuletzt bearbeitet 15.05.2026 17:15:03
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorpo...
CVE-2026-33132
- EPSS 0.31%
- Veröffentlicht 20.03.2026 10:21:19
- Zuletzt bearbeitet 23.03.2026 18:06:26
ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users to bypass organization enforcement during authentication. Zitadel allows applications to enforce an organzation context during auth...
CVE-2026-32132
- EPSS 0.4%
- Veröffentlicht 11.03.2026 21:40:07
- Zuletzt bearbeitet 16.03.2026 16:52:31
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An impr...
CVE-2026-32131
- EPSS 0.39%
- Veröffentlicht 11.03.2026 21:38:51
- Zuletzt bearbeitet 16.03.2026 16:52:22
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant...
CVE-2026-32130
- EPSS 0.58%
- Veröffentlicht 11.03.2026 21:37:07
- Zuletzt bearbeitet 16.03.2026 16:51:59
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with...
CVE-2026-29193
- EPSS 0.31%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 10.03.2026 17:52:35
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even ...
CVE-2026-29192
- EPSS 0.32%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 10.03.2026 17:54:28
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Default URI Redirect. This issue has been patched in ver...