
⚠️ Critical ZITADEL Flaw Enables 1-Click Account Takeover https://cyberpress.org/1-click-vulnerability-in-zitadel/ A critical vulnerability in the IAM platform ZITADEL (CVE-2026-29191) allows attackers to execute arbitrary JavaScript in a victim’s browser with a single malicious link. The flaw affects versions 4.0.0–4.11.1 and stems from an XSS issue in the /saml-post endpoint used in SAML authentication flows. Successful exploitation could allow attackers to trigger password resets and potentially take over accounts. The issue has been fixed in version 4.12.0, and organizations are advised to update immediately. #CyberSecurity #Infosec #Vulnerability
Post summary
ZITADEL's CVE-2026-29191 is a critical XSS flaw enabling one‑click account takeover via arbitrary JavaScript; the issue is fixed in 4.12.0 and organizations should update immediately.












