5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Basic Information
ID
CVE-2026-23511
Source
GitHub_M
Published
Jan 15, 2026 at 19:09
Modified
Jan 15, 2026 at 19:56
Affected Product
Vendor
zitadel
Product
zitadel
Version
>= 4.0.0, < 4.9.1
Affected Versions
zitadel zitadel >= 4.0.0, < 4.9.1
zitadel zitadel < 3.4.6
zitadel zitadel < 3.4.6
CWE Classification
References
- github.com /zitadel/zitadel/security/advisories/GHSA-pvm5-9frx-264r
- github.com /zitadel/zitadel/commit/b85ab69e4679b0268e2b0e9b4cd04e934af10dd2
- github.com /zitadel/zitadel/commit/c300d4cc6a2775ab17ddfe76492f24170f8b858d
- github.com /zitadel/zitadel/releases/tag/v3.4.6
- github.com /zitadel/zitadel/releases/tag/v4.9.1