Impact
ZITADEL versions prior to 4.17.1 fail to verify an organization’s inactive status during Login V2 authentication, checking only the individual user’s state. As a result, any user belonging to a deactivated organization who possesses valid credentials, an existing session, or a refresh token can sign in, create new sessions, and obtain or refresh tokens. This flaw enables unauthorized access and could allow an attacker to retrieve confidential data, modify resources, or perform actions with the user’s privileges.
Affected Systems
The affected product is ZITADEL, the identity management platform created by ZITADEL. All releases that belong to the 4.x series and precede version 4.17.1 are impacted; the exact sub‑versions are not enumerated in the advisory, so any build before 4.17.1 should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. No EPSS score is available, but the lack of mitigating factors and the straightforward nature of the bypass suggest a non‑negligible likelihood of exploitation. The vulnerability is listed as not being in CISA’s KEV catalog. Attackers can exploit it remotely by issuing Login V2 requests over the network; the only prerequisite is possession of valid credentials or token artifacts for a user within a deactivated organization, making the attack accessible to anyone who can acquire such credentials or tokens.
OpenCVE Enrichment