CVE-2026-27945
Last modified
CVE-2026-27945 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such the issue of a token. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such the issue of a token. Zitadel's Action target URLs can point to local hosts, potentially allowing adversaries to gather internal network information and connect to internal services. When the URL points to a local host / IP address, an adversary might gather information about the internal network structure, the services exposed on internal hosts etc. This is sometimes called a Server-Side Request Forgery (SSRF). Zitadel Actions expect responses according to specific schemas, which reduces the threat vector. The patch in version 4.11.1 resolves the issue by checking the target URL against a denylist. By default localhost, resp. loopback IPs are denied. Note that this fix was only released on v4.x. Due to the stage (preview / beta) in which the functionality was in v2.x and v3.x, the changes that have been applied to it since then and the severity, respectively the actual thread vector, a backport to the corresponding versions was not feasible. Please check the workaround section for alternative solutions if an upgrade to v4.x is not possible. If an upgrade is not possible, prevent actions from using unintended endpoints by setting network policies or firewall rules in one's own infrastructure. Note that this is outside of the functionality provided by Zitadel.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zitadel | Zitadel | >= 2.59.0, <= 3.4.6 |
| Zitadel | Zitadel | >= 4.0.0, < 4.11.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27945?
How severe is CVE-2026-27945?
How do I fix CVE-2026-27945?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2794Information disclosure due to uninitialized memory in Firefo…7.5
- CVE-2026-27940llama.cpp is an inference of several LLM models in C/C++. Pr…7.8
- CVE-2026-27941OpenLIT is an open source platform for AI engineering. Prior…9.9
- CVE-2026-27942fast-xml-parser allows users to validate XML, parse XML to J…7.5
- CVE-2026-27943OpenEMR is a free and open source electronic health records …6.5
- CVE-2026-27944Nginx UI is a web user interface for the Nginx web server. P…9.8
- CVE-2026-27946ZITADEL is an open source identity management platform. Prio…6.5
- CVE-2026-27947Group-Office is an enterprise customer relationship manageme…8.8
- CVE-2026-27948Copyparty is a portable file server. In versions prior to 1.…6.1
- CVE-2026-27949Plane is an an open-source project management tool. Prior to…4.3
- CVE-2026-2795Use-after-free in the JavaScript: GC component. This vulnera…9.8
- CVE-2026-27950FreeRDP is a free implementation of the Remote Desktop Proto…7.5
Are you affected by CVE-2026-27945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
