Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/zitadel/zitadel

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

ZITADEL versions 4.x prior to 4.17.1 do not verify whether an organization is inactive during Login V2 authentication, only checking the individual user's status. This allows users belonging to deactivated organizations who have valid credentials, existing sessions, or refresh tokens to continue signing in, creating sessions, and obtaining or refreshing tokens.

Join the discussion

ZITADEL versions before 3.4.14 and 4.x before 4.16.2 have an authentication bypass vulnerability in the hosted Login V1 UI. The flaw arises because the 'external account not found' registration endpoint trusts client-supplied external identity fields without verifying a completed identity provider (IdP) callback. This allows unauthenticated attackers to forge IDPConfigID and ExternalUserID values to pre-create accounts linked to a victim's external IdP identity. When the victim later logs in via the genuine external IdP, they are signed into the attacker-created account.

Join the discussion

ZITADEL versions 3.x before 3.4.14 and 4.x before 4.16.2 contain an authentication bypass vulnerability in the hosted Login V1 and Login V2 user interfaces. This flaw allows unauthenticated attackers who know a victim's login name to register an attacker-controlled authenticator during identify-only login sessions before any primary factor verification. As a result, attackers can log in as the victim without needing the victim's password or multi-factor authentication.

Join the discussion

ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 have a vulnerability where links between user accounts and external identity providers are created without verifying a primary authentication factor or the caller's permission. This allows an unauthenticated attacker who knows a victim's login name to link their own external identity provider identity to the victim's account and subsequently sign in as that victim.

Join the discussion

ZITADEL versions 3.x before 3.4.15 and 4.x before 4.17.1 contain an improper authorization vulnerability. The flaw occurs when issuing passkey or passwordless enrollment codes, where the system verifies only the organization in the x-zitadel-orgid header instead of the target user's organization. This allows attackers with user-write permission in one organization to obtain enrollment codes for users in other organizations on the same instance and register their own authenticators, effectively taking over those accounts.

Join the discussion

ZITADEL versions 3.x before 3.4.15 and 4.x before 4.17.1 contain an authentication flaw in the hosted Login V1 UI. The flaw allows attackers who know only a victim's login name to enroll attacker-controlled second-factor authentication methods without verifying the primary factor. This includes enrolling TOTP, OTP-SMS, OTP-Email, or U2F factors, overwriting verified phone numbers, and enumerating users via error discrepancies.

Join the discussion

ZITADEL versions 3.0.0 through 3.4.15 and 4.x before 4.17.3 contain an authorization flaw in the User Service API. The flaw causes the system to verify user.read permissions against the caller's organization instead of the organization owning the target user. This allows an authenticated user with org-scoped user.read permission to query authentication methods of users in other organizations via the GET /v2/users/{userId}/authentication_methods endpoint.

Join the discussion

ZITADEL versions 4.x before 4.17.3 and 3.x through 3.4.15 use unauthenticated, malleable encryption to protect IdP intent tokens. This flaw allows authenticated users to tamper with their own tokens to impersonate another user's external login intent. An attacker who can predict a victim's in-flight intent identifier and win a timing race may steal the victim's IdP tokens or hijack their session.

Join the discussion

Zitadel versions prior to 4.16.2 contain a server-side request forgery (SSRF) vulnerability. This flaw allows attackers to exploit the organization domain HTTP verification process to make the server request internal resources. The vulnerability arises because the challenge fetch uses Go's default http.Get method instead of a protected client, enabling attackers to register domains that redirect to loopback, internal, or cloud metadata addresses. This can be used to scan ports and map internal networks.

Join the discussion

ZITADEL versions before 4.17.1 have an authentication bypass vulnerability in the Login V2 component. This flaw allows unauthenticated attackers to take over accounts by exploiting the returnCode delivery type to obtain OTP codes. Attackers who know a victim's login name and that the victim has OTP-Email and OTP-SMS enrolled can read both OTP codes from server responses, enabling them to gain MFA-authenticated sessions, including administrator accounts.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Package: pkg:github/zitadel/zitadel
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses