CVE-2026-32130
Last modified
CVE-2026-32130 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with URL-encoded path values were correctly routed but would bypass necessary authentication and permission checks. This allowed unauthenticated attackers to retrieve sensitive information such as names, email addresses, phone numbers, addresses, external IDs, and roles. Note that due to additional checks when manipulating data, an attacker could not modify or delete any user data. This vulnerability is fixed in 3.4.8 and 4.12.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zitadel | Zitadel | >= 2.68.0, < 3.4.8 |
| Zitadel | Zitadel | >= 4.0.0, < 4.12.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-32130?
How severe is CVE-2026-32130?
How do I fix CVE-2026-32130?
Are you affected by CVE-2026-32130?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
