CVE-2025-64717 is a critical vulnerability in ZITADEL versions 2.50.0 through 2.71.18, 3.4.3, and 4.6.5, allowing unauthenticated attackers to bypass security controls during the federation process. The flaw enables auto-linking of external identity provider (IdP) accounts to existing ZITADEL users, even when the IdP is disabled or federation is disallowed by the organization. This can lead to full account takeover for accounts without multi-factor authentication (MFA). Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability has a network attack vector, low attack complexity, and requires no user interaction, resulting in high impacts to confidentiality, integrity, and availability. The root cause is a failure to properly enforce organization-specific security settings during the authentication flow, specifically CWE-287 (Improper Authentication). There is no evidence of active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. However, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential interest in developing exploits. Organizations are advised to upgrade to ZITADEL versions 2.71.19, 3.4.4, or 4.6.6 immediately, as no other workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.50.0, < 2.71.19CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.4.4CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.6.6CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.