PT-2026-65854 · Zitadel · Zitadel

CVE-2026-54693

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 2.43.0 through 2.71.19 ZITADEL versions 3.0.0 through 3.4.10 ZITADEL versions 4.0.0 through 4.15.0
Description An improper permission check in the self-management API allows authenticated users to request verification codes for emails and phone numbers without the necessary permissions. This flaw enables users to claim ownership of contact details they do not control, potentially bypassing security policies based on email or phone verification. The issue resides in the API paths handled by internal/command/user v2 email.go, internal/command/user v2 phone.go, and internal/command/user v2 human.go.
Recommendations Update ZITADEL versions 2.43.0 through 2.71.19 to version 3.4.11 or later. Update ZITADEL versions 3.0.0 through 3.4.10 to version 3.4.11 or later. Update ZITADEL versions 4.0.0 through 4.15.0 to version 4.15.1 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54693
GHSA-JQ8W-8Q2F-FFM9

Affected Products

Zitadel