Account Takeover Vulnerability in ZITADEL Identity Management Platform
CVE-2026-29192

7.7HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-29192?

An issue was identified within ZITADEL's login V2 interface that allowed for potential account takeover through a Default URI Redirect method. This vulnerability impacts ZITADEL versions from 4.0.0 to 4.11.1 and has been addressed in version 4.12.0. Users are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

zitadel >= 4.0.0, < 4.12.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.