CVE-2026-32132

HIGH

ZITADEL <3.4.8/4.12.2 - Auth Bypass

Title source: llm
STIX 2.1

Description

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the code, could allow an attacker to potentially register their own passkey and gain access to the victim's account. This vulnerability is fixed in 3.4.8 and 4.12.2.

Scores

CVSS v3 7.4
EPSS 0.0004
EPSS Percentile 13.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-613
Status published
Products (2)
zitadel/zitadel < 3.4.8
zitadel/zitadel 4.0.0 - 4.12.2
Published Mar 11, 2026
Tracked Since Mar 12, 2026