CVE-2026-29192
7.7Zitadel · ZITADEL
ZITADEL versions 4.0.0 through 4.11.1 contain a vulnerability in the login V2 interface that allows for account takeover via a Default URI Redirect.
Executive summary
A vulnerability in the ZITADEL identity management platform allows for potential account takeover, posing a significant risk to organizational authentication security.
Vulnerability
The flaw is an Improper Neutralization of Input during web page generation (CWE-79), which manifests as a Cross-site Scripting vulnerability within the login V2 interface. This issue permits an authenticated attacker with high privileges to facilitate a Default URI Redirect, leading to unauthorized account takeover.
Business impact
The ability to perform account takeover within an identity management platform represents a critical threat to the entire security architecture of an organization. An attacker who successfully exploits this flaw can gain administrative control over the platform, potentially compromising all downstream applications and user identities managed by ZITADEL. With a CVSS score of 7.7, this is a high-severity issue that requires immediate attention to prevent unauthorized access and systemic data breaches.
Remediation
Immediate Action: Update the ZITADEL platform to version 4.12.0 or later to apply the official security patch.
Proactive Monitoring: Monitor authentication logs for unusual redirect patterns or abnormal administrative activities originating from the login V2 interface.
Compensating Controls: Ensure that Web Application Firewall (WAF) rules are configured to inspect and block suspicious URI redirection attempts and malformed inputs targeting the authentication flow.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the central role of ZITADEL in identity management, the risk of account takeover is severe. Administrators must prioritize the transition to version 4.12.0 immediately to eliminate this vulnerability. Failure to patch allows a persistent risk of administrative compromise, which could have cascading impacts on all integrated services and user accounts.