CVE-2026-23511

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

History

20 Jan 2026, 16:44

Type Values Removed Values Added
CPE cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
First Time Zitadel
Zitadel zitadel
References () https://github.com/zitadel/zitadel/commit/b85ab69e4679b0268e2b0e9b4cd04e934af10dd2 - () https://github.com/zitadel/zitadel/commit/b85ab69e4679b0268e2b0e9b4cd04e934af10dd2 - Patch
References () https://github.com/zitadel/zitadel/commit/c300d4cc6a2775ab17ddfe76492f24170f8b858d - () https://github.com/zitadel/zitadel/commit/c300d4cc6a2775ab17ddfe76492f24170f8b858d - Patch
References () https://github.com/zitadel/zitadel/releases/tag/v3.4.6 - () https://github.com/zitadel/zitadel/releases/tag/v3.4.6 - Release Notes
References () https://github.com/zitadel/zitadel/releases/tag/v4.9.1 - () https://github.com/zitadel/zitadel/releases/tag/v4.9.1 - Release Notes
References () https://github.com/zitadel/zitadel/security/advisories/GHSA-pvm5-9frx-264r - () https://github.com/zitadel/zitadel/security/advisories/GHSA-pvm5-9frx-264r - Third Party Advisory

15 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 20:16

Updated : 2026-01-20 16:44


NVD link : CVE-2026-23511

Mitre link : CVE-2026-23511

CVE.ORG link : CVE-2026-23511


JSON object : View

Products Affected

zitadel

  • zitadel
CWE
CWE-204

Observable Response Discrepancy