PT-2026-23104 · Zitadel · Zitadel

Amit-Laish

·

Published

2026-03-04

·

Updated

2026-03-25

·

CVE-2026-29191

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.11.1
Description ZITADEL, an open source identity management platform, contains a cross-site scripting (XSS) issue in its login V2 interface, specifically within the /saml-post endpoint. This flaw allows for potential account takeover by enabling the execution of malicious JavaScript code in a victim’s browser. The issue stems from insecure redirection using the url parameter and reflection of user-supplied input without proper HTML encoding. An unauthenticated attacker can exploit this by crafting a malicious link, potentially resetting passwords and gaining control of accounts. The vulnerability does not require SAML integration to be exploited and can affect Zitadel in its default configuration. The /saml-post endpoint accepts the url and id parameters.
Recommendations Upgrade to ZITADEL version 4.12.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29191
GHSA-PR34-2V5X-6QJQ
GO-2026-4607
SUSE-SU-2026:1042-1

Affected Products

Zitadel