IDOR Vulnerability in Zitadel Identity Management Platform
CVE-2025-64431

8.7HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-64431?

The Zitadel Identity Management Platform is susceptible to insecure Direct Object Reference (IDOR) attacks through its V2Beta API. This vulnerability allows authenticated users with specific administrator roles to access and alter organization-level data belonging to other entities within the system. Affected data includes organization names, domains, and metadata, though sensitive information such as users and applications remain secure. This issue was remedyed in version 4.6.3, making it crucial for users to update their installations.

Affected Version(s)

zitadel >= 4.0.0-rc.1, < 4.6.3 < 4.0.0-rc.1, 4.6.3

zitadel >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52 < 1.80.0-v2.20.0.20250414095945-f365cee73242, 1.80.0-v2.20.0.20251105083648-8dcfff97ed52

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64431 : IDOR Vulnerability in Zitadel Identity Management Platform