PT-2026-23861 · Zitadel · Zitadel

Amit-Laish

·

Published

2025-12-08

·

Updated

2026-03-12

·

CVE-2026-29067

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0-rc.1 through 4.7.0
Description ZITADEL is an open source identity management platform. A potential issue exists in ZITADEL’s password reset mechanism in login V2. The platform uses the Forwarded or X-Forwarded-Host header from incoming requests to build the URL for the password reset confirmation link, which includes a secret code and is sent to the user via email.
Recommendations Update to version 4.7.1 or later.

Exploit

Fix

DoS

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-29067
GHSA-PFRF-9R5F-73F5
GO-2025-4212

Affected Products

Zitadel