CVE-2026-54693

zitadel · zitadel

An incorrect authorization vulnerability in the ZITADEL identity management platform allows for unauthorized integrity impacts.

Executive summary

An authorization flaw in ZITADEL versions 2.x, 3.x, and 4.x allows unauthorized users to perform sensitive actions, posing a significant risk to identity management security.

Vulnerability

This is an incorrect authorization vulnerability (CWE-863) that allows unauthorized parties to manipulate system integrity. The vulnerability affects the platform's identity management functions and does not require prior authentication to trigger.

Business impact

As an identity management platform, ZITADEL is a critical component of security architecture. An authorization bypass could lead to unauthorized access to user accounts or administrative functions, undermining the entire security posture of the organization. The CVSS score of 8.2 reflects the high impact on system integrity.

Remediation

Immediate Action: Organizations must update the ZITADEL platform to version 3.4.11 or 4.15.1, or the specific fixed release identified in the OSV data, to resolve the authorization flaw.

Proactive Monitoring: Review audit logs for unauthorized changes to user roles, permissions, or identity configurations that may indicate exploitation of this flaw.

Compensating Controls: Ensure that sensitive management interfaces are restricted to trusted network segments and require multi-factor authentication for all administrative access.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the central role of ZITADEL in managing organizational identities, this vulnerability must be patched immediately. Failure to update the software could result in unauthorized administrative actions and the compromise of identity data.