PT-2026-23106 · Zitadel · Zitadel

Amit-Laish

·

Published

2026-03-04

·

Updated

2026-03-25

·

CVE-2026-29193

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.12.0
Description ZITADEL, an open source identity management platform, had a flaw in its login V2 UI. This allowed users to circumvent login behavior and security policies, enabling self-registration of new accounts or sign-in with passwords even when these options were disabled by the organization's administrators. An attacker could send direct HTTP requests to the login UI to create accounts in organizations where self-registration was disabled, and gain unauthorized access. The same attack vector could be used to authenticate with a username and password even when this login method was disabled.
Recommendations Upgrade to version 4.12.1 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29193
GHSA-25RW-G6FF-FMG8
GO-2026-4604
SUSE-SU-2026:1042-1

Affected Products

Zitadel