CRITICAL🇵🇱 Wersja polska

CVE-2025-27507

CVSS 9.0v3.1pub. 2025-03-04upd. 2025-08-26

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users, without specific IAM roles, to modify sensitive settings. While several endpoints are affected, the most critical vulnerability lies in the ability to manipulate LDAP configurations. Customers who do not utilize LDAP for authentication are not at risk from the most severe aspects of this vulnerability. However, upgrading to the patched version to address all identified issues is strongly recommended. This vulnerability is fixed in 2.71.0, 2.70.1, ,2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5, and 2.63.8.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient permission verification for specific Admin API endpoints — an attacker can directly reference objects and modify their values, bypassing IAM role controls. The most critical vector concerns manipulation of LDAP configuration, which may allow changing identity provider settings. The vulnerability requires possession of an active account in the system, but does not require assignment of special administrative privileges.

Impact

An attacker with access to an account without privileged IAM roles can modify sensitive identity management system settings, including LDAP configuration, which may lead to breach of confidentiality and integrity of authentication data and the entire identity environment.

Mitigation & patch

Update Zitadel to one of the patched versions: 2.71.0, 2.70.1, 2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5 or 2.63.8. Organizations not using LDAP should still deploy the patch, as the vulnerability also affects other Admin API endpoints. Details available in the official security advisory on GitHub.

Who is affected

Zitadel in all versions preceding: 2.71.0, 2.70.1, 2.69.4, 2.68.4, 2.67.8, 2.66.11, 2.65.6, 2.64.5 and 2.63.8. The most serious risk concerns environments using LDAP as an authentication mechanism.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
  • Zitadel

    APP
    Zitadel
    < 2.63.82.64.0 – 2.64.5 (excl.)2.65.0 – 2.65.6 (excl.)2.66.0 – 2.66.11 (excl.)2.67.0 – 2.67.8 (excl.)2.68.0 – 2.68.4 (excl.)2.69.0 – 2.69.4 (excl.)2.70.0 – 2.70.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
IDOR
CWE
References

Related vulnerabilities

CVE-2026-29191CRITICAL9.3PL ✓same product

XSS w Zitadel Login V2 — możliwe przejęcie konta przez /saml-post

CVE-2025-67494CRITICAL9.3PL ✓same product

SSRF bez uwierzytelnienia w ZITADEL — odczyt wewnętrznych zasobów sieciowych

CVE-2026-44671HIGH7.5same product

ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerabil...

CVE-2026-32131HIGH7.7same product

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel'...

CVE-2026-32130HIGH7.5same product

ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provid...