PT-2026-104637 · Zitadel · Zitadel
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.x through 4.17.0
Description
Login V2 authentication fails to verify the inactive state of an organization, checking only the status of the individual user. This allows users belonging to a deactivated organization to sign in, create sessions, and obtain or refresh tokens if they possess valid credentials, an existing session, or a refresh token.
Recommendations
Update ZITADEL to version 4.17.1.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel