The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specific IAM roles, to modify sensitive settings. While several endpoints are affected, the most critical vulnerability lies in the ability to manipulate LDAP configurations. Customers who do not utilize LDAP for authentication are not at risk from the most severe aspects of this vulnerability. However, upgrading to the patched version to address all identified issues is strongly recommended. This vulnerability is fixed in 2.71.0, 2.70.1, ,2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5, and 2.63.8.
The vulnerability consists of insufficient permission verification for specific Admin API endpoints — an attacker can directly reference objects and modify their values, bypassing IAM role controls. The most critical vector concerns manipulation of LDAP configuration, which may allow changing identity provider settings. The vulnerability requires possession of an active account in the system, but does not require assignment of special administrative privileges.
An attacker with access to an account without privileged IAM roles can modify sensitive identity management system settings, including LDAP configuration, which may lead to breach of confidentiality and integrity of authentication data and the entire identity environment.
Update Zitadel to one of the patched versions: 2.71.0, 2.70.1, 2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5 or 2.63.8. Organizations not using LDAP should still deploy the patch, as the vulnerability also affects other Admin API endpoints. Details available in the official security advisory on GitHub.
Zitadel in all versions preceding: 2.71.0, 2.70.1, 2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5 and 2.63.8. The most serious risk concerns environments using LDAP as an authentication mechanism.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:LZitadel
APPZitadel< 2.63.82.64.0 – 2.64.5 (excl.)2.65.0 – 2.65.6 (excl.)2.66.0 – 2.66.11 (excl.)2.67.0 – 2.67.8 (excl.)2.68.0 – 2.68.4 (excl.)2.69.0 – 2.69.4 (excl.)2.70.0 – 2.70.1 (excl.)
Related vulnerabilities
XSS w Zitadel Login V2 — możliwe przejęcie konta przez /saml-post
SSRF bez uwierzytelnienia w ZITADEL — odczyt wewnętrznych zasobów sieciowych
ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerabil...
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel'...
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provid...