MikeTrendsTrends right now

search

ZITADEL

Trends

  1. 1
    ZITADEL hit by seven vulnerabilities enabling account takeover●ZITADEL cluster — 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header → issue passkey enrollment for anyMmastodonTechnologyCybersecurity21 d ago

    Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.

  2. 2
    Zitadel IAM flagged with D trust score over unpatched flaws●Zitadel IAM carries a D trust score: 41 CVEs, max CVSS 9.3, and 97% left unpatched. Auth flaws (CWE-287) recur. Know youMmastodonTechnologyCybersecurity04 d ago

    Security analyst Hugo Valters reports that Zitadel, the open-source identity and access management platform, carries a D trust score based on 41 published CVEs, a maximum severity of 9.3, and 97% of vulnerabilities left unpatched. Authentication flaws classified under CWE-287 recur in the vendor's history. He urges organisations to assess their exposure before deploying the software.