PT-2026-65854 · Zitadel · Zitadel
CVE-2026-54693
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 2.43.0 through 2.71.19
ZITADEL versions 3.0.0 through 3.4.10
ZITADEL versions 4.0.0 through 4.15.0
Description
An improper permission check in the self-management API allows authenticated users to request verification codes for emails and phone numbers without the necessary permissions. This flaw enables users to claim ownership of contact details they do not control, potentially bypassing security policies based on email or phone verification. The issue resides in the API paths handled by
internal/command/user v2 email.go, internal/command/user v2 phone.go, and internal/command/user v2 human.go.Recommendations
Update ZITADEL versions 2.43.0 through 2.71.19 to version 3.4.11 or later.
Update ZITADEL versions 3.0.0 through 3.4.10 to version 3.4.11 or later.
Update ZITADEL versions 4.0.0 through 4.15.0 to version 4.15.1 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel