CVE-2026-23511

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-15 20:16

Updated : 2026-01-20 16:44


NVD link : CVE-2026-23511

Mitre link : CVE-2026-23511

CVE.ORG link : CVE-2026-23511


JSON object : View

Products Affected

zitadel

  • zitadel
CWE
CWE-204

Observable Response Discrepancy