Vulnerabilities in zitadel

59 results
Vexday analysis

Zitadel apresenta 57 vulnerabilidades catalogadas, com 3 críticas e nenhuma sob ataque ativo identificado. A fraqueza dominante é CWE-287 (falhas em autenticação), padrão esperado em solução de identidade, mas com 10 divulgações nos últimos 90 dias indicando ciclo ativo de descobertas que requerem monitoramento contínuo.

CVE-2025-67494CRITICALZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 LoginEPSS 0.4%CVE-2025-46815HIGHZITADEL Allows IdP Intent Token ReuseEPSS 0.4%CVE-2023-46238HIGHXSS with User Avatar image in ZITADELEPSS 0.4%CVE-2026-55672HIGHZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)EPSS 0.4%CVE-2026-55671LOWZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP ComponentsEPSS 0.4%CVE-2026-56668HIGHZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token ExchangeEPSS 0.4%CVE-2024-47000HIGHService Users Deactivation not Working in ZitadelEPSS 0.4%CVE-2026-23511MEDIUMZITADEL has a user enumeration vulnerability in Login UIsEPSS 0.4%CVE-2026-29191CRITICALZITADEL: 1-Click Account Takeover via XSS in /saml-post EndpointEPSS 0.4%CVE-2026-32132HIGHZITADEL: Reactivation of Expired Passkey Registration CodesEPSS 0.4%CVE-2025-48936HIGHZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header InjectionEPSS 0.4%CVE-2026-32131HIGHZITADEL Cross-Tenant Information Disclosure in Management APIEPSS 0.4%CVE-2025-31123HIGHZitadel Expired JWT Keys Usable for Authorization GrantsEPSS 0.4%CVE-2026-56667HIGHZITADEL: Stored XSS via Default URI Redirect in Login V2EPSS 0.4%CVE-2025-57770MEDIUMZITADEL user enumeration vulnerability in login UIEPSS 0.4%CVE-2025-53895HIGHZITADEL has broken authN and authZ in session API and resulting session tokensEPSS 0.4%CVE-2026-55670LOWZITADEL: Cross-Tenant User Leakage via Recycled IdentifiersEPSS 0.4%CVE-2024-47060MEDIUMUnauthorized Access After Organization or Project Deactivation in ZitadelEPSS 0.4%CVE-2024-46999HIGHUser Grant Deactivation not Working in ZitadelEPSS 0.4%CVE-2025-64102HIGHZitadel allows brute-forcing authentication factorsEPSS 0.3%