Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zitadel

First CVE: Aug 31, 2022Active for: 4 yearsTotal CVEs: 47
45.3
VTI Score
High

Zitadel is an open-source identity and access management platform that, despite a narrowly focused product portfolio, occupies a prominent position in the authentication and authorization infrastructure landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across its core IAM offering through weakness classes centered on improper input neutralization and cross-site scripting, authorization flaws, authentication bypass conditions, and exposure of sensitive credentials or session data. These vulnerability classes reflect the inherent complexity of identity systems: the handling of user input, token generation, permission evaluation, and credential storage across web-facing endpoints. Defenders deploying Zitadel as a centralized authentication service should prioritize this vendor's advisories, since flaws in IAM logic or web-layer protections can compromise access to downstream applications. Current exploitation activity, severity distribution, and remediation urgency are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
9.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zitadel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2022
3 years ago
Most Recent CVE
May 14, 2026
71 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-64717CRITICAL
ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process
Nov 13, 20259.834NONO
CVE-2026-29191CRITICAL
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account
Mar 7, 20269.333NONO
CVE-2026-29067CRITICAL
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADE
Mar 7, 20269.331NONO
CVE-2026-44671HIGH
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation,
May 14, 20267.530NONO
CVE-2025-64103CRITICAL
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a
Oct 29, 20259.830NONO
CVE-2025-64102CRITICAL
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. While
Oct 29, 20259.830NONO
CVE-2025-67494HIGH
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treat
Dec 9, 20258.629NONO
CVE-2025-64101HIGH
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilize
Oct 29, 20258.829NONO
CVE-2026-29193HIGH
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security p
Mar 7, 20268.228NONO
CVE-2025-27507CRITICAL
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference
Mar 4, 20259.028NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
45%
38%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network46 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low41 (87.2%)
High6 (12.8%)
Unknown0 (0.0%)
User Interaction
None34 (72.3%)
Unknown0 (0.0%)
Required13 (27.7%)
Privileges Required
Low11 (23.4%)
High5 (10.6%)
None31 (66.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.1% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zitadel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zitadel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zitadel's Products

View all 1 CNAs →

Top CWEs