Impact
The vulnerability stems from an incorrect authorization check in ZITADEL's User Service API, which validates the `user.read` permission against the caller's organization rather than the organization that owns the target user. As a result, an authenticated member with org‑scoped `user.read` may query `/v2/users/{userId}/authentication_methods` and discover the authentication method types registered by users belonging to other organizations. This breach of access control exposes information about authentication mechanisms that could aid credential‑reuse attacks or facilitate targeted phishing. The flaw is classified as CWE‑863, a broken access control defect.
Affected Systems
Affected products are ZITADEL, version 3.0.0 through 3.4.15 and 4.x prior to 4.17.3. Any deployment that has not applied the patch in version 4.17.3 (or the corresponding 3.4.16 fix) is vulnerable. The issue is limited to the User Service API and does not propagate across the entire platform; however, the data it exposes is sensitive enough to warrant immediate attention for any environment that hosts multiple organizations.
Risk and Exploitability
The CVSS base score of 5.3 places the vulnerability in the medium severity range, and the EPSS score is currently unavailable, so the likelihood of exploitation is not quantified. The problem is not listed in CISA's KEV catalog. Successful exploitation requires the attacker to be authenticated with at least org‑scoped `user.read` permissions, which is a relatively high‑privilege level but commonly granted to operational users. Once authenticated, the attacker can use the exposed endpoint to enumerate authentication methods across organizations.
OpenCVE Enrichment