
`ZITADEL` users can bypass email/phone verification via the UpdateHumanUser API (CVE-2026-27946). This impacts account integrity. Monitor for official patches. #ZITADEL #AuthBypass #Infosec https://www.pulsepatch.io/posts/cve-2026-27946-zitadel-self-verification-bypass
Post summary
ZITADEL's UpdateHumanUser API can bypass email/phone verification, threatening account integrity; users should monitor for official patches.


