Description
ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
Published: 2026-10-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Method Enumeration / Cross-Organization Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from an incorrect authorization check in ZITADEL's User Service API, which validates the `user.read` permission against the caller's organization rather than the organization that owns the target user. As a result, an authenticated member with org‑scoped `user.read` may query `/v2/users/{userId}/authentication_methods` and discover the authentication method types registered by users belonging to other organizations. This breach of access control exposes information about authentication mechanisms that could aid credential‑reuse attacks or facilitate targeted phishing. The flaw is classified as CWE‑863, a broken access control defect.

Affected Systems

Affected products are ZITADEL, version 3.0.0 through 3.4.15 and 4.x prior to 4.17.3. Any deployment that has not applied the patch in version 4.17.3 (or the corresponding 3.4.16 fix) is vulnerable. The issue is limited to the User Service API and does not propagate across the entire platform; however, the data it exposes is sensitive enough to warrant immediate attention for any environment that hosts multiple organizations.

Risk and Exploitability

The CVSS base score of 5.3 places the vulnerability in the medium severity range, and the EPSS score is currently unavailable, so the likelihood of exploitation is not quantified. The problem is not listed in CISA's KEV catalog. Successful exploitation requires the attacker to be authenticated with at least org‑scoped `user.read` permissions, which is a relatively high‑privilege level but commonly granted to operational users. Once authenticated, the attacker can use the exposed endpoint to enumerate authentication methods across organizations.

Generated by OpenCVE AI on October 4, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to 4.17.3 or later (or 3.4.16 and above)
  • Restrict or revoke org‑scoped `user.read` permissions so that only administrators can query authentication methods, and ensure permissions cannot be granted to users who should not have cross‑organization visibility
  • If an upgrade is not immediately possible, temporarily disable the `/v2/users/{userId}/authentication_methods` endpoint or modify it to enforce ownership checks in your custom code

Generated by OpenCVE AI on October 4, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
Title ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-863
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:01.420Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105206

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:31.517

Modified: 2026-10-04T15:16:31.627

Link: CVE-2026-105206

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T19:30:05Z

Weaknesses