We found results for “”
CVE-2026-23511
Good to know:
Date: January 15, 2026
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Severity Score
Related Resources (9)
Severity Score
Top Fix
Upgrade Version
Upgrade to version github.com/zitadel/zitadel - v4.9.1;github.com/zitadel/zitadel - v3.4.6;https://github.com/zitadel/zitadel.git - v4.9.1;https://github.com/zitadel/zitadel.git - v3.4.6
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


