zitadel
Security Productscommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting zitadel.
- CVE-2026-56668ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange8.1
- CVE-2026-56666ZITADEL: Auto-linking by email: IdP-side email verification is not checked4.8
- CVE-2026-56667ZITADEL: Stored XSS via Default URI Redirect in Login V27.3
- CVE-2026-56665ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider4.2
- CVE-2026-56664ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider4.2
- CVE-2026-55672ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)7.4
- CVE-2026-55669ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider4.2
- CVE-2026-44671ZITADEL: LDAP Filter Injection in Login Flow7.5
- CVE-2026-33132ZITADEL is missing enforcement of organization scopes5.3
- CVE-2026-32132ZITADEL: Reactivation of Expired Passkey Registration Codes7.4
- CVE-2026-32131ZITADEL Cross-Tenant Information Disclosure in Management API7.7
- CVE-2026-32130ZITADEL SCIM Authentication Bypass via URL Encoding7.5
- CVE-2026-29067ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login8.1
- CVE-2026-29193ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V28.2
- CVE-2026-29192ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover7.7