Vulnerability in ZITADEL Actions V1 Allows File System Access and Potential Credential Disclosure
CVE-2026-85057

8.7HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-85057?

ZITADEL, an open source identity management platform, has a vulnerability in its Actions V1 feature, present in versions 3.0.0 through 3.4.13 and 4.16.1. The issue arises from the inadequate restriction on the goja Node-compatible require() registry, allowing an authorized Action author with specific permissions to execute JavaScript at critical points of user authentication, including OIDC and SAML login triggers. This flaw enables the unauthorized access of files that are readable by the ZITADEL server process, which may lead to the disclosure of sensitive configuration details and credentials. Consequently, this could facilitate privilege escalation from an organization administrator to an instance administrator. The vulnerability has been addressed in later versions, specifically 3.4.13 and 4.16.1.

Affected Version(s)

zitadel >= 3.0.0, < 3.4.13 < 3.0.0, 3.4.13

zitadel >= 4.0.0, < 4.16.1 < 4.0.0, 4.16.1

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.