PT-2026-104630 · Zitadel · Zitadel

·

CVE-2026-105206

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 3.0.0 through 3.4.15 ZITADEL versions prior to 4.17.3
Description An incorrect authorization flaw exists in the User Service API. The system verifies the user.read permission against the caller's organization instead of the organization that owns the target user. An authenticated member with org-scoped user.read permissions can use the 'GET /v2/users/{userId}/authentication methods' endpoint to identify the authentication method types registered by users in other organizations.
Recommendations Update ZITADEL versions 3.0.0 through 3.4.15 to a patched version. Update ZITADEL versions prior to 4.17.3 to version 4.17.3 or later. Restrict access to the 'GET /v2/users/{userId}/authentication methods' endpoint to minimize the risk of unauthorized information disclosure.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105206

Affected Products

Zitadel