ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant.read, or project.app.read) to retrieve management-plane information belonging to other organizations by specifying a different tenant’s project_id, grant_id, or app_id. This vulnerability is fixed in 3.4.8 and 4.12.2.
References
| Link | Resource |
|---|---|
| https://github.com/zitadel/zitadel/releases/tag/v3.4.8 | Product |
| https://github.com/zitadel/zitadel/releases/tag/v4.12.2 | Product |
| https://github.com/zitadel/zitadel/security/advisories/GHSA-wr6r-59xg-4pj2 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Mar 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/zitadel/zitadel/releases/tag/v3.4.8 - Product | |
| References | () https://github.com/zitadel/zitadel/releases/tag/v4.12.2 - Product | |
| References | () https://github.com/zitadel/zitadel/security/advisories/GHSA-wr6r-59xg-4pj2 - Vendor Advisory | |
| First Time |
Zitadel
Zitadel zitadel |
|
| Summary |
|
|
| CPE | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
11 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 22:16
Updated : 2026-03-16 16:52
NVD link : CVE-2026-32131
Mitre link : CVE-2026-32131
CVE.ORG link : CVE-2026-32131
JSON object : View
Products Affected
zitadel
- zitadel
