Vulnerability in ZITADEL Actions V1 Allows File System Access and Potential Credential Disclosure
CVE-2026-85057
What is CVE-2026-85057?
ZITADEL, an open source identity management platform, has a vulnerability in its Actions V1 feature, present in versions 3.0.0 through 3.4.13 and 4.16.1. The issue arises from the inadequate restriction on the goja Node-compatible require() registry, allowing an authorized Action author with specific permissions to execute JavaScript at critical points of user authentication, including OIDC and SAML login triggers. This flaw enables the unauthorized access of files that are readable by the ZITADEL server process, which may lead to the disclosure of sensitive configuration details and credentials. Consequently, this could facilitate privilege escalation from an organization administrator to an instance administrator. The vulnerability has been addressed in later versions, specifically 3.4.13 and 4.16.1.
Affected Version(s)
zitadel >= 3.0.0, < 3.4.13 < 3.0.0, 3.4.13
zitadel >= 4.0.0, < 4.16.1 < 4.0.0, 4.16.1
