Threats Tagged 'cve-2026-54693'
View all threats tagged with 'cve-2026-54693'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-54693'
Click on any threat for detailed analysis and mitigation recommendations
ZITADEL Users Can Self-Verify Email/Phone via API (CVE-2026-54693)CVE-2026-54693 0 A vulnerability in Zitadel's user self-management API allowed users to mark their email and phone as verified without completing the actual verification process. This was due to improper permission checks that enabled users to retrieve verification codes for email and phone numbers they do not control. The issue affects Zitadel versions 4.0.0 through 4.15.0, 3.0.0 through 3.4.10, and 2.43.0 through 2.71.19. The vulnerability has been fixed in versions 4.15.1 and later, 3.4.11 and later, and 3.4.11 and later for the respective branches. Users are advised to upgrade to these patched versions to mitigate the risk. If upgrading is not possible, a workaround exists to prevent returning verification codes to the user. Join the discussion | GCVE Database | 07/29/2026, 16:54:49 UTC Added: 07/30/2026, 05:46:51 UTC |
Showing 1 to 1 of 1 result