← Back

CVE-2026-32132

nvd nist
Published: Mar 11, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: security-advisories@github.com (Secondary)

Description

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the code, could allow an attacker to potentially register their own passkey and gain access to the victim's account. This vulnerability is fixed in 3.4.8 and 4.12.2.

Affected (2)

Products: Zitadel: Zitadel
1 product
Zitadel
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Zitadel
Before 3.4.8
From 4.0.0 to 4.12.2

References (3)

Source: security-advisories@github.com
Product
Source: security-advisories@github.com
Product
Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.