CVE-2026-29193

8.2

Zitadel · Zitadel

A vulnerability in the Zitadel login V2 UI allows unauthenticated users to bypass security policies, enabling unauthorized account self-registration and password-based authentication.

Executive summary

A critical authentication bypass vulnerability in Zitadel versions 4.0.0 through 4.12.0 allows unauthenticated attackers to circumvent security policies and gain unauthorized account access.

Vulnerability

The flaw is an improper authentication issue (CWE-287) located within the login V2 UI component. It allows an unauthenticated attacker to bypass organizational security settings, effectively permitting unauthorized account creation and access.

Business impact

The ability for unauthorized parties to self-register accounts or bypass disabled authentication methods poses a severe risk to identity integrity and organizational security. Given the CVSS score of 8.2, this vulnerability represents a high risk for unauthorized data access and potential account takeover. Successful exploitation undermines the fundamental trust model of the identity management platform, which could lead to significant downstream data breaches.

Remediation

Immediate Action: Update all instances of Zitadel to version 4.12.1 or later to apply the necessary security patches.

Proactive Monitoring: Review authentication and user creation logs for anomalous activity, specifically looking for accounts created outside of established provisioning workflows or unexpected login attempts.

Compensating Controls: While no direct virtual patch is specified, ensure that network-level access controls restrict external visibility to the login V2 UI if the service is not intended for public-facing use.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this authentication bypass necessitates immediate remediation. Organizations relying on Zitadel for identity management must prioritize the upgrade to version 4.12.1 to prevent unauthorized access and maintain the integrity of their identity infrastructure. Failure to patch allows attackers to bypass core security policies, creating a direct path to system compromise.

More Zitadel CVEs

Sources