CVE-2026-29193 describes a vulnerability in ZITADEL, an open-source identity management platform, affecting versions 4.0.0 through 4.12.0. This flaw in the login V2 UI allowed users to bypass configured security policies, enabling self-registration of new accounts or password-based sign-ins even when these options were disabled by an organization. With a CVSS score of 8.2 (High), this vulnerability is easily exploitable over the network with low complexity and no user interaction, potentially leading to high confidentiality impact and low integrity impact. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention, and there is no media coverage. The issue has been patched in ZITADEL version 4.12.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.12.1CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.