Record summary

CVE-2026-29192 has a selected CVSS score of 7.7 (high).

Description

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Default URI Redirect. This issue has been patched in version 4.12.0.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 9, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List>= 4.0.0, < 4.12.0affected

github.com/zitadel/zitadel

Browse Go / github.com/zitadel/zitadel
GitHub Advisory4.0.0 to < 4.12.0 · Fixed in 4.12.0affected

github.com/zitadel/zitadel/v2

Browse Go / github.com/zitadel/zitadel/v2
GitHub Advisory4.0.0 to < 4.12.0 · Fixed in 4.12.0affected

References

4