FlawAtlas
Search the atlas
CVE-2026-29193 High

ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication in github.com/zitadel/zitadel

ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel from v4.0.0 before v4.12.1.

Exploit probability 0.3%
Published March 10, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

42 explicit affected versions

Go github.com/zitadel/zitadel
Go github.com/zitadel/zitadel
Go github.com/zitadel/zitadel/v2

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-29193

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton. This issue has been patched in version 4.12.1.

View original source
Open Source Vulnerabilities GHSA-25rw-g6ff-fmg8

### Summary A vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton. ### Impact Zitadel enables administrators to configure their organization’s login behavior and security policies. As part of this functionality, they can disable user self-registration, enforce passwordless logins only, and more. Due to improper enforcement an attacker could send direct HTTP requests to the login UI and create accounts in organizations that have disabled user self-registration, and gain unauthorized access to the system. The same attack vector could be used to authenticate for example using username and password even when this login method was disabled. ### Affected Versions Systems running one of the following versions are affected: - **4.x**: `4.0.0` through `4.12.0` (including RC versions) ### Patches The vulnerability has been addressed in the latest releases. The patch resolves the issue by enforcing the policies on the logiin UI server. 4.x: Upgrade to >=[4.12.1](https://github.com/zitadel/zitadel/releases/tag/v4.12.1) ### Workarounds The recommended solution is to upgrade to a patched version. ### Questions If there are any questions or comments about this advisory, please send an email to [[email protected]](mailto:[email protected]) ### Credits ZITADEL extends thanks once again to Amit Laish from GE Vernova for finding and reporting the vulnerability.

View original source
Open Source Vulnerabilities GO-2026-4604

ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication in github.com/zitadel/zitadel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/zitadel/zitadel from v4.0.0 before v4.12.1.

View original source

05 / REFERENCES

Further evidence