CVE-2026-27946Disclosure(zitadel / zitadel)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zitadel zitadel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. The patch in versions 4.11.1 and 3.4.7 resolves the issue by requiring the correct permission in case the verification flag is provided and only allows self-management of the email address and/or phone number itself. If an upgrade is not possible, an action (v2) could be used to prevent setting the verification flag on the own user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zitadel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
zitadel

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-03-30: 1Patch / Workaround · 2026-03-30: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-30: 102-2602-2703-30
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `ZITADEL` users can bypass email/phone verification via the UpdateHumanUser API (CVE-2026-27946). This impacts account integrity. Monitor for official patches. #ZITADEL #AuthBypass #Infosec https://www.pulsepatch.io/posts/cve-2026-27946-zitadel-self-verification-bypass

    Post summary

    ZITADEL's UpdateHumanUser API can bypass email/phone verification, threatening account integrity; users should monitor for official patches.

    0000040
    5 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27946: ZITADEL Authorization Bypass: Self-Verification of Email and Phone A high-severity authorization bypass vulnerability in ZITADEL allows authenticated users to self-verify their email addresses and phone numbers via the V2 User API. By ... https://cvereports.com/reports/CVE-2026-27946

    Post summary

    The post announces a high‑severity authorization bypass in ZITADEL, where authenticated users can self‑verify email addresses and phone numbers through the V2 User API.

    0000054
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27946 ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to m… https://www.cve.org/CVERecord?id=CVE-2026-27946

    Post summary

    The text announces a vulnerability in Zitadel’s self‑management feature, noting affected versions but providing no further technical details or mitigation information.

    00000117
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzitadelzitadel---

Explore more