IDOR Vulnerability in Zitadel Identity Management Platform
CVE-2025-64431
What is CVE-2025-64431?
The Zitadel Identity Management Platform is susceptible to insecure Direct Object Reference (IDOR) attacks through its V2Beta API. This vulnerability allows authenticated users with specific administrator roles to access and alter organization-level data belonging to other entities within the system. Affected data includes organization names, domains, and metadata, though sensitive information such as users and applications remain secure. This issue was remedyed in version 4.6.3, making it crucial for users to update their installations.
Affected Version(s)
zitadel >= 4.0.0-rc.1, < 4.6.3 < 4.0.0-rc.1, 4.6.3
zitadel >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52 < 1.80.0-v2.20.0.20250414095945-f365cee73242, 1.80.0-v2.20.0.20251105083648-8dcfff97ed52
