Zitadel is an open-source identity and access management platform that, despite a narrowly focused product portfolio, occupies a prominent position in the authentication and authorization infrastructure landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across its core IAM offering through weakness classes centered on improper input neutralization and cross-site scripting, authorization flaws, authentication bypass conditions, and exposure of sensitive credentials or session data. These vulnerability classes reflect the inherent complexity of identity systems: the handling of user input, token generation, permission evaluation, and credential storage across web-facing endpoints. Defenders deploying Zitadel as a centralized authentication service should prioritize this vendor's advisories, since flaws in IAM logic or web-layer protections can compromise access to downstream applications. Current exploitation activity, severity distribution, and remediation urgency are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zitadel over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64717CRITICAL ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process | Nov 13, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-29191CRITICAL ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account | Mar 7, 2026 | 9.3 | 33 | NO | NO |
CVE-2026-29067CRITICAL ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADE | Mar 7, 2026 | 9.3 | 31 | NO | NO |
CVE-2026-44671HIGH ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, | May 14, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-64103CRITICAL Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a | Oct 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-64102CRITICAL Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While | Oct 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-67494HIGH ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treat | Dec 9, 2025 | 8.6 | 29 | NO | NO |
CVE-2025-64101HIGH Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilize | Oct 29, 2025 | 8.8 | 29 | NO | NO |
CVE-2026-29193HIGH ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security p | Mar 7, 2026 | 8.2 | 28 | NO | NO |
CVE-2025-27507CRITICAL The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference | Mar 4, 2025 | 9.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zitadel.
Media articles that mention a CVE ID that affects a product developed by Zitadel — matched by CVE ID, not by vendor name.