Zitadel
This hub aggregates every CVE we track for Zitadel, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Enterprise Softwareweb app
54
CVEs tracked
6
Critical
26
High
0
In CISA KEV
Severity distribution
HIGH26MEDIUM22CRITICAL6
Monthly trend
0
3
2
0
0
0
0
3
0
2
0
1
1
0
3
1
3
1
3
8
0
1
0
7
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Zitadel.
- CVE-2026-56668ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange8.1
- CVE-2026-56666ZITADEL: Auto-linking by email: IdP-side email verification is not checked4.8
- CVE-2026-56667ZITADEL: Stored XSS via Default URI Redirect in Login V27.3
- CVE-2026-56665ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider4.2
- CVE-2026-56664ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider4.2
- CVE-2026-55672ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)7.4
- CVE-2026-55669ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider4.2
- CVE-2026-44671ZITADEL: LDAP Filter Injection in Login Flow7.5
- CVE-2026-33132ZITADEL is missing enforcement of organization scopes5.3
- CVE-2026-32132ZITADEL: Reactivation of Expired Passkey Registration Codes7.4
- CVE-2026-32131ZITADEL Cross-Tenant Information Disclosure in Management API7.7
- CVE-2026-32130ZITADEL SCIM Authentication Bypass via URL Encoding7.5
- CVE-2026-29067ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login8.1
- CVE-2026-29193ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V28.2
- CVE-2026-29192ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover7.7
Product normalization is registry-driven with AI assist and human review. How it works