CVE-2026-23511

Z

ITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

History

20 Jan 2026, 16:44

Type Values Removed Values Added
First Time Zitadel
Zitadel zitadel
CPE cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
References () https://github.com/zitadel/zitadel/commit/b85ab69e4679b0268e2b0e9b4cd04e934af10dd2 - () https://github.com/zitadel/zitadel/commit/b85ab69e4679b0268e2b0e9b4cd04e934af10dd2 - Patch
References () https://github.com/zitadel/zitadel/commit/c300d4cc6a2775ab17ddfe76492f24170f8b858d - () https://github.com/zitadel/zitadel/commit/c300d4cc6a2775ab17ddfe76492f24170f8b858d - Patch
References () https://github.com/zitadel/zitadel/releases/tag/v3.4.6 - () https://github.com/zitadel/zitadel/releases/tag/v3.4.6 - Release Notes
References () https://github.com/zitadel/zitadel/releases/tag/v4.9.1 - () https://github.com/zitadel/zitadel/releases/tag/v4.9.1 - Release Notes
References () https://github.com/zitadel/zitadel/security/advisories/GHSA-pvm5-9frx-264r - () https://github.com/zitadel/zitadel/security/advisories/GHSA-pvm5-9frx-264r - Third Party Advisory

15 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 20:16

Updated : 2026-01-20 16:44


NVD link : CVE-2026-23511

Mitre link : CVE-2026-23511

CVE.ORG link : CVE-2026-23511


JSON object : View

Products Affected
CWE
CWE-204

Observable Response Discrepancy