CVE-2026-23511

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Configurations

No configuration.

History

15 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 20:16

Updated : 2026-01-16 15:55


NVD link : CVE-2026-23511

Mitre link : CVE-2026-23511

CVE.ORG link : CVE-2026-23511


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy