Authentication Bypass in ZITADEL Identity Management Platform
CVE-2026-32130
7.5HIGH
What is CVE-2026-32130?
ZITADEL, a popular open-source identity management platform, has a vulnerability in its System for Cross-domain Identity Management (SCIM) API. This vulnerability allows unauthenticated attackers to bypass crucial authentication and permission checks, enabling them to retrieve sensitive information such as names, email addresses, phone numbers, and roles associated with users. However, attackers are restricted from modifying or deleting user data due to additional protective measures. The vulnerability affects versions of ZITADEL from 2.68.0 prior to 3.4.8 and 4.12.2, and it has been addressed in the updates released for these versions.
Affected Version(s)
zitadel >= 4.0.0, < 4.12.2 < 4.0.0, 4.12.2
zitadel >= 2.68.0, < 3.4.8 < 2.68.0, 3.4.8
