CVE-2026-29191Disclosure(zitadel / zitadel)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch zitadel zitadel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zitadel

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 12 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-03-07); latest day: 1
  • 14 total mentions across 6 days

Affected systems

Vendors
Products
zitadel

Deep dive

Activity timeline14 mentions / 6d
01345Mentions · 2026-03-05: 2Mentions · 2026-03-07: 5Mentions · 2026-03-09: 4Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1PoC Mentioned / Linked · 2026-03-07: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-09: 3Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-07: 4Technical Details · 2026-03-09: 4Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 103-0503-0703-0903-1003-1203-16
Signal classification3 categories
Disclosure
750.0%
Patch
642.9%
General
17.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-052
Patch2
2026-03-075
Disclosure4Patch1
2026-03-094
Disclosure2Patch2
2026-03-101
General1
2026-03-121
Disclosure1
2026-03-161
Patch1
Full discourse14 posts
  • Hunt.io@Huntio
    Disclosure

    ⚠️ Critical ZITADEL Flaw Enables 1-Click Account Takeover https://cyberpress.org/1-click-vulnerability-in-zitadel/ A critical vulnerability in the IAM platform ZITADEL (CVE-2026-29191) allows attackers to execute arbitrary JavaScript in a victim’s browser with a single malicious link. The flaw affects versions 4.0.0–4.11.1 and stems from an XSS issue in the /saml-post endpoint used in SAML authentication flows. Successful exploitation could allow attackers to trigger password resets and potentially take over accounts. The issue has been fixed in version 4.12.0, and organizations are advised to update immediately. #CyberSecurity #Infosec #Vulnerability

    Post summary

    ZITADEL's CVE-2026-29191 is a critical XSS flaw enabling one‑click account takeover via arbitrary JavaScript; the issue is fixed in 4.12.0 and organizations should update immediately.

    2401431.3K
    5.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.3 CVSS XSS vulnerability (CVE-2026-29191) in ZITADEL's SAML endpoint allows unauthenticated 1-click account takeover. Upgrade immediately. #ZITADEL #CyberSecurity #XSS #AccountTakeover #IAM #InfoSec #Vulnerability #PatchAlert #AppSec https://securityonline.info/1-click-to-compromise-critical-9-3-cvss-flaw-in-zitadel-exposes-accounts-to-full-takeover/ https://t.co/CKqMMEzaGt

    Post summary

    The tweet announces a critical 9.3 CVSS XSS flaw in ZITADEL’s SAML endpoint that allows unauthenticated one‑click account takeover, urging users to upgrade immediately.

    120111657
    10.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical #XSS Account Takeover in #ZITADEL. CVE-2026-29191 CVSS: 9.3. This flaw in Login V2 /saml-post can enable account takeover and then lead to serious compromise. #Patch #Patch #Patch

    Post summary

    The post warns of a critical XSS flaw (CVE‑2026‑29191) in ZITADEL with a high CVSS score, notes patch availability, but provides no exploit details or evidence of active use.

    00000221
    7.2K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-29191 (CVSS:9.3, CRITICAL) is Analyzed. ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login..https://nvd.nist.gov/vuln/detail/CVE-2026-29191 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑29191, a critical login vulnerability affecting ZITADEL 4.0.0–4.11.1, has been documented with CVSS 9.3 and is listed on NVD.

    0000021
    172 followersView on X
  • VulnTracker@vuln_tracker
    General

    @Huntio CVE-2026-29191 in ZITADEL is exactly the kind of identity platform vulnerability that keeps security teams up at night. Thanks for the clear breakdown and visual presentation! We've had added this CVE on our dashboard: https://vulntracker.io/cves/CVE-2026-29191

    Post summary

    The tweet acknowledges the CVE-2026-29191 in ZITADEL, thanks for a clear breakdown, but provides no evidence of exploitation, patches or detailed vulnerability information.

    0000046
    394 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 One-click ZITADEL flaw enables browser-based account takeover and full IAM compromise A critical ZITADEL vulnerability, CVE-2026-29191, lets unauthenticated attackers abuse the `/saml-post` endpoint to execute JavaScript in a victim’s browser with a single click, enabling password resets and account takeover. This matters because the bug affects a widely used IAM platform and can be exploited even when SAML is not enabled, turning a phishing link into a direct identity-layer compromise. 🎯 Target: Global/Organizations Using ZITADEL #️⃣ Category: #Vulnerability #TargetedAttacks #BlueTeam 🔗 URL: https://cyberpress.org/1-click-vulnerability-in-zitadel/

    Post summary

    The post announces CVE-2026-29191, detailing a one-click browser-based account takeover vulnerability that allows unauthenticated attackers to run JavaScript via ZITADEL’s `/saml-post` endpoint.

    0000056
    273 followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @the_yellow_fall Thanks for highlighting CVE-2026-29191! ZITADEL SAML endpoint XSS leading to 1-click account takeover is exactly why identity platforms need extra security attention. That 9.3 CVSS score says it all - time to upgrade! https://vulntracker.io/cves/CVE-2026-29191

    Post summary

    The tweet highlights a high‑severity XSS flaw (CVE‑2026‑29191) in ZITADEL’s SAML endpoint that permits 1‑click account takeover, urging customers to apply a patch immediately.

    0000048
    394 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29191 ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a po… https://www.cve.org/CVERecord?id=CVE-2026-29191

    Post summary

    The text announces CVE-2026-29191 affecting Zitadel login V2 (v4.0.0–4.11.1), notes a proof‑of‑concept was disclosed, but provides no exploit details, patch information, or evidence of active exploitation.

    00000116
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29191 ZITADEL XSS Vulnerability in Login V2 Interface Enables Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29191

    Post summary

    The post reports a new XSS vulnerability in ZITADEL’s Login V2 interface that could allow attackers to take over user accounts.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29191: CRITICAL] Critical security update for ZITADEL users! A vulnerability in login interface allows account takeover via XSS attack. Update to version 4.12.0 to stay protected. #cybersecurity#cve,CVE-2026-29191,#cybersecurity https://cvefind.com/CVE-2026-29191

    Post summary

    The post announces a critical XSS flaw in ZITADEL’s login interface that permits account takeover, urging users to update to version 4.12.0.

    0000055
    599 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29191 - Critical ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeov... https://www.thehackerwire.com/vulnerability/CVE-2026-29191/ https://t.co/018ubefLTz

    Post summary

    A critical vulnerability (CVE-2026-29191) in ZITADEL's login V2 interface could enable account takeover, but no PoC, exploit, or patch details are provided.

    0000036
    128 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-29191: ZITADEL: 1-Click Account Takeove... SAML POST endpoint XSS with 9.3 CVSS means one malicious link = full identity platform compromise across 12 major versi... https://zerodaysignal.com/vulnerability/CVE-2026-29191 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new high‑severity XSS flaw (CVE‑2026‑29191) in ZITADEL’s SAML POST endpoint is disclosed, potentially compromising entire identity platforms via a single malicious link.

    0000071
    140 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 CVE-2026-29191 in Zitadel’s /saml-post endpoint could enable account takeover via XSS attacks. Upgrade to version 4.12.0+ immediately. Workarounds may help temporarily, but patching is the recommended fix. 🔍 https://vulert.com/vuln-db/CVE-2026-29191 #CyberSecurity #XSS #Vulert https://t.co/RClVJ8rsXD

    Post summary

    The tweet announces a CVE-2026-29191 XSS vulnerability in Zitadel and urges users to upgrade to version 4.12.0+, providing temporary workarounds and stressing patching as the fix.

    0000044
    124 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `ZITADEL` deployments are affected by an XSS vulnerability (CVE-2026-29191) in the SAML post endpoint, enabling account takeover. Upgrade to 4.12.0 or later. #ZITADEL #XSS #infosec https://www.pulsepatch.io/posts/cve-2026-29191-zitadel-xss-account-takeover

    Post summary

    CVE-2026-29191 is an XSS flaw in ZITADEL’s SAML post endpoint that can lead to account takeover; upgrading to version 4.12.0 or newer resolves the issue.

    0000028
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzitadelzitadel---

Explore more