PT-2025-34464 · Zitadel · Zitadel
Adksrijan
+1
·
Published
2025-08-22
·
Updated
2025-08-26
·
CVE-2025-57770
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Zitadel versions 4.0.0 through 4.0.2
Zitadel versions 3.0.0 through 3.3.6
Zitadel versions prior to 2.71.15
Description:
Zitadel allows administrators to disable user self-registration. A username enumeration issue exists in the login interface due to a bypass of the 'Ignoring unknown usernames' security feature. An unauthenticated attacker can submit arbitrary userIDs to the select account page and differentiate between valid and invalid accounts based on the system's response. Exploitation involves iterating through possible userIDs, but rate limiting can mitigate the impact.
Recommendations:
Update to Zitadel version 4.0.3 or later.
Update to Zitadel version 3.4.0 or later.
Update to Zitadel version 2.71.15 or later.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel