CVE-2026-54693
zitadel · zitadel
An incorrect authorization vulnerability in the ZITADEL identity management platform allows for unauthorized integrity impacts.
Executive summary
An authorization flaw in ZITADEL versions 2.x, 3.x, and 4.x allows unauthorized users to perform sensitive actions, posing a significant risk to identity management security.
Vulnerability
This is an incorrect authorization vulnerability (CWE-863) that allows unauthorized parties to manipulate system integrity. The vulnerability affects the platform's identity management functions and does not require prior authentication to trigger.
Business impact
As an identity management platform, ZITADEL is a critical component of security architecture. An authorization bypass could lead to unauthorized access to user accounts or administrative functions, undermining the entire security posture of the organization. The CVSS score of 8.2 reflects the high impact on system integrity.
Remediation
Immediate Action: Organizations must update the ZITADEL platform to version 3.4.11 or 4.15.1, or the specific fixed release identified in the OSV data, to resolve the authorization flaw.
Proactive Monitoring: Review audit logs for unauthorized changes to user roles, permissions, or identity configurations that may indicate exploitation of this flaw.
Compensating Controls: Ensure that sensitive management interfaces are restricted to trusted network segments and require multi-factor authentication for all administrative access.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the central role of ZITADEL in managing organizational identities, this vulnerability must be patched immediately. Failure to update the software could result in unauthorized administrative actions and the compromise of identity data.