8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belonging to other organizations. Note that this vulnerability is limited to organization-level data (name, domains, metadata). No other related data (such as users, projects, applications, etc.) is affected. This issue is fixed in version 4.6.3.
AI Analysis
Secure Direct Object Reference (IDOR) vulnerability in Zitadel's V2Beta API, allowing authenticated users with specific administrator roles to access and modify data belonging to other organizations.
Basic Information
ID
CVE-2025-64431
Source
GitHub_M
Published
Nov 7, 2025 at 18:09
Modified
Nov 7, 2025 at 18:29
Affected Product
Vendor
zitadel
Product
zitadel
Version
>= 4.0.0-rc.1, < 4.6.3
Affected Versions
zitadel zitadel >= 4.0.0-rc.1, < 4.6.3
zitadel zitadel >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52
zitadel zitadel >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Zitadel
Product
Zitadel Identity Management Platform
Version
4.0.0-rc.1 to 4.6.2