Record summary

CVE-2026-27946 has a selected CVSS score of 8.2 (high).

Description

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. The patch in versions 4.11.1 and 3.4.7 resolves the issue by requiring the correct permission in case the verification flag is provided and only allows self-management of the email address and/or phone number itself. If an upgrade is not possible, an action (v2) could be used to prevent setting the verification flag on the own user.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 26, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 4.0.0, < 4.11.0affected
< 3.4.7affected

github.com/zitadel/zitadel

Browse Go / github.com/zitadel/zitadel
GitHub Advisory4.0.0 to < 4.11.1 · Fixed in 4.11.1affected
2.43.0 to < 3.4.7 · Fixed in 3.4.7affected
Before 1.80.0-v2.20.0.20260225053417-0261536243e5 · Fixed in 1.80.0-v2.20.0.20260225053417-0261536243e5affected

References

6