Identity Management Platform Vulnerability in ZITADEL
CVE-2025-64717
What is CVE-2025-64717?
A vulnerability exists in ZITADEL that allows unauthorized auto-linking of users from external identity providers to existing accounts, bypassing organizational security settings. This flaw enables an attacker to leverage a disabled identity provider to gain access to user accounts, potentially leading to account takeover if specific settings are not enforced properly. The issue affects ZITADEL versions prior to 2.71.19, 3.4.4, and 4.6.6, which have been updated to ensure adherence to organizations' login policies during the authentication process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zitadel >= 4.0.0-rc.1, < 4.6.6 < 4.0.0-rc.1, 4.6.6
zitadel >= 3.0.0-rc.1, < 3.4.4 < 3.0.0-rc.1, 3.4.4
zitadel >= 2.50.0, < 2.71.19 < 2.50.0, 2.71.19
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
