CVE-2026-85057
8.7ZITADEL · ZITADEL
ZITADEL Actions V1 contains an improper access control vulnerability allowing authenticated organization administrators to read sensitive files from the server, potentially leading to privilege escalation.
Executive summary
An improper access control vulnerability in ZITADEL Actions V1 allows privileged users to read server configuration files and escalate privileges to the instance administrator level.
Vulnerability
The vulnerability exists in the goja Node-compatible require registry within ZITADEL Actions V1, which fails to restrict its filesystem source loader. An authenticated user with specific organization management permissions can exploit this to access arbitrary files readable by the server process, including sensitive credentials.
Business impact
Successful exploitation poses a severe risk to the identity management environment, as it allows an organization administrator to bypass security boundaries and gain instance-level administrative control. This unauthorized access can lead to total compromise of the identity provider, including the theft of OIDC and SAML secrets. Given the CVSS score of 8.7, this is considered a high-severity risk requiring immediate attention to prevent unauthorized access to critical authentication infrastructure.
Remediation
Immediate Action: Upgrade ZITADEL to version 3.4.13 or 4.16.1, as these releases contain the necessary security patches to restrict the filesystem source loader.
Proactive Monitoring: Review audit logs for suspicious activity originating from organization administrators, specifically monitoring for unusual file access attempts or modifications to Actions.
Compensating Controls: Restrict the ability to create or modify Actions to a strictly limited set of trusted personnel until the patch can be applied to the environment.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The ability for an internal attacker to escalate privileges to the instance level represents a critical failure in the security model of the ZITADEL platform. Organizations using affected versions of ZITADEL must prioritize the deployment of the provided security updates. Failure to patch this vulnerability could lead to a complete compromise of the underlying identity infrastructure.
More ZITADEL CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- https://github.com/zitadel/zitadel/security/advisories/GHSA-fgmf-7rf8-m6vf
- https://github.com/zitadel/zitadel/commit/afe108640cf57a17e8b743fbcdad9ae636eb3eb7
- https://github.com/zitadel/zitadel/commit/baf6ed501b684f47048553d9034e8d3aa824950e
- https://github.com/zitadel/zitadel/commit/e28d6bcc033368c3e9683ee15c195b8460b9305d
- https://github.com/zitadel/zitadel/releases/tag/v3.4.13
- https://github.com/zitadel/zitadel/releases/tag/v4.16.1