CVE 8.7 HIGH

IDOR Vulnerabilities in ZITADEL’s Organization API allows Cross-Tenant Data Tempering_CVE-2025-64431

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) attacks through its V2Beta API, allowing authenticated users with specific administrator roles within one organization to access and modify data belonging to other organizations. Note that this vulnerability is limited to organization-level data (name, domains, metadata). No other related data (such as users, projects, applications, etc.) is affected. This issue is fixed in version 4.6.3.

AI Analysis

Secure Direct Object Reference (IDOR) vulnerability in Zitadel's V2Beta API, allowing authenticated users with specific administrator roles to access and modify data belonging to other organizations.

Basic Information

ID CVE-2025-64431
Source GitHub_M
Published Nov 7, 2025 at 18:09
Modified Nov 7, 2025 at 18:29

Affected Product

Vendor zitadel
Product zitadel
Version >= 4.0.0-rc.1, < 4.6.3
Affected Versions zitadel zitadel >= 4.0.0-rc.1, < 4.6.3
zitadel zitadel >= 1.80.0-v2.20.0.20250414095945-f365cee73242, < 1.80.0-v2.20.0.20251105083648-8dcfff97ed52

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Zitadel
Product Zitadel Identity Management Platform
Version 4.0.0-rc.1 to 4.6.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.