ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6. | |
| Title | ZITADEL has a user enumeration vulnerability in Login UIs | |
| Weaknesses | CWE-204 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-15T19:56:24.164Z
Reserved: 2026-01-13T18:22:43.979Z
Link: CVE-2026-23511
Updated: 2026-01-15T19:56:21.421Z
Status : Received
Published: 2026-01-15T20:16:05.167
Modified: 2026-01-15T20:16:05.167
Link: CVE-2026-23511
No data.
OpenCVE Enrichment
No data.