logo

1-Click to Compromise: Critical 9.3 CVSS Flaw in ZITADEL Exposes Accounts to Full Takeover

ID: 8de2c403-d06c-5be4-a95c-d98c75a0f3ac

STIX ID: report--8de2c403-d06c-5be4-a95c-d98c75a0f3ac

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed CVE-2026-29191, a critical (CVSS 9.3) vulnerability in ZITADEL's Login V2 SAML handling that allows unauthenticated attackers to trigger a javascript: open-redirect and reflected XSS via the /saml-post endpoint, enabling remote account takeover (e.g., forced password resets); versions 4.0.0–4.11.1 are affected, a patch is available in 4.12.0+, MFA/passwordless mitigates risk, and temporary mitigation is to block /saml-post with a WAF or proxy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.