CVE-2026-54693
Last modified
CVE-2026-54693 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to request returned verification codes without the required permission, allowing users to claim ownership of email addresses or phone numbers they do not control and bypass email-based or phone-based security policies. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to request returned verification codes without the required permission, allowing users to claim ownership of email addresses or phone numbers they do not control and bypass email-based or phone-based security policies. This issue is fixed in versions 3.4.11 and 4.15.1.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zitadel | zitadel | >= 2.43.0, <= 2.71.19; >= 3.0.0-rc.1, < 3.4.11; >= 4.0.0-rc.1, < 4.15.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54693?
How severe is CVE-2026-54693?
How do I fix CVE-2026-54693?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54684jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a mal…7
- CVE-2026-54685FileBrowser Quantum is a free, self-hosted, web-based file m…5.3
- CVE-2026-54686Warp is an agentic development environment. From 0.2021.04.2…4.3
- CVE-2026-5469A weakness has been identified in Casdoor 2.356.0. This vuln…7.2
- CVE-2026-54690datamodel-code-generator generates Pydantic v2 models, datac…8.2
- CVE-2026-54691datamodel-code-generator generates Python data models from s…8.2
- CVE-2026-54695Pipecat is an open-source Python framework for building real…6.5
- CVE-2026-54696Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 …3.7
- CVE-2026-54698Hasura is an open-source product that provides users GraphQL…6
- CVE-2026-54699Warp is an agentic development environment. From 0.2024.03.1…7.7
- CVE-2026-5470A security vulnerability has been detected in mixelpixx Goog…6.3
- CVE-2026-54704OpenTelemetry Java Instrumentation provides OpenTelemetry au…6.5
Are you affected by CVE-2026-54693?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
