Threat Advisory

ZITADEL Flaws Expose Server Control and Host Data Retrieval

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting ZITADEL Actions V1 and Login V2 UI have been identified. These vulnerabilities collectively present a high risk to organizations using these components particularly those that have granted org.action.write or org.flow.write permissions to untrusted administrators.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting ZITADEL Actions V1 and Login V2 UI have been identified. These vulnerabilities collectively present a high risk to organizations using these components particularly those that have granted org.action.write or org.flow.write permissions to untrusted administrators.[emaillocker id="1283"]

CVE-2026-85057 (CVSS 8.7 — High): A vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript require module loader, which can be chained to steal bootstrap credentials and escalate privileges.

CVE-2026-85056 (CVSS 8.2 — High): A vulnerability in ZITADEL's Login V2 UI allowed a password-verified browser session to be reused for a new authentication request without re-checking the user's enrolled second factor, enabling MFA bypass via session reuse.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-fgmf-7rf8-m6vf
https://github.com/advisories/GHSA-9993-rfwp-rhwf

[/emaillocker]
crossmenu