PT-2026-98201 · Zitadel · Zitadel
CVE-2026-85057
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 3.0.0 through 3.4.12
ZITADEL versions 4.0.0 through 4.16.0
Description
ZITADEL Actions V1 allows an organization Action author with
ORG OWNER, org.action.write, and org.flow.write permissions to read files from the host filesystem. This occurs because the goja Node-compatible require() registry is enabled without restricting its filesystem source loader, allowing JavaScript to be executed at OIDC, SAML, and login-flow trigger points to load files readable by the ZITADEL server process. This can lead to the disclosure of mounted configurations and secrets, such as credentials stored via ZITADEL FIRSTINSTANCE LOGINCLIENTPATPATH or ZITADEL FIRSTINSTANCE MACHINEKEYPATH. Consequently, an attacker can escalate privileges from an organization administrator to an instance administrator. Host command execution is not possible.Recommendations
Update ZITADEL versions 3.0.0 through 3.4.12 to version 3.4.13.
Update ZITADEL versions 4.0.0 through 4.16.0 to version 4.16.1.
Restrict the assignment of
org.action.write, org.flow.write, or ORG OWNER permissions to untrusted administrators.
Remove or relocate bootstrap credential files, such as login-client.pat and machine keys, to ensure they are not readable within the API process filesystem.
Limit the host filesystem exposure for the ZITADEL process by removing unnecessary readable secrets.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel