PT-2026-104630 · Zitadel · Zitadel
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 3.0.0 through 3.4.15
ZITADEL versions prior to 4.17.3
Description
An incorrect authorization flaw exists in the User Service API. The system verifies the
user.read permission against the caller's organization instead of the organization that owns the target user. An authenticated member with org-scoped user.read permissions can use the 'GET /v2/users/{userId}/authentication methods' endpoint to identify the authentication method types registered by users in other organizations.Recommendations
Update ZITADEL versions 3.0.0 through 3.4.15 to a patched version.
Update ZITADEL versions prior to 4.17.3 to version 4.17.3 or later.
Restrict access to the 'GET /v2/users/{userId}/authentication methods' endpoint to minimize the risk of unauthorized information disclosure.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel