← Back

CVE-2026-23511

nvd nist
Published: Jan 15, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.

Affected (3)

Products: Zitadel: Zitadel
1 product
Zitadel
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Zitadel
From 2.0.0 to 2.71.19
From 3.0.0 to 3.4.6
From 4.0.0 to 4.9.1

References (5)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Third Party Advisory

Timeline

No history available yet.