logo

1-Click ZITADEL Vulnerability Could Allow Full System Takeover

ID: bf7871a7-613e-58f7-98e0-a9b42fbbef27

STIX ID: report--bf7871a7-613e-58f7-98e0-a9b42fbbef27

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-09

Date Updated: 2026-04-22

Author: Divya

...
...

A critical XSS vulnerability (CVE-2026-29191) in ZITADEL's /saml-post endpoint allows unauthenticated attackers to execute JavaScript in users' browsers via crafted links, enabling silent password resets and full account takeover; the issue affects default installations of versions 4.0.0–4.11.1 and is fixed in 4.12.0. Immediate remediation steps are to upgrade to 4.12.0 or higher, enforce MFA or passwordless authentication, and, if immediate upgrading is infeasible, block access to the vulnerable endpoint with a WAF or reverse-proxy rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.