๐Ÿ” CVE Alert

CVE-2026-54693

UNKNOWN 0.0

ZITADEL Users Can Self-Verify Email/Phone via API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to request returned verification codes without the required permission, allowing users to claim ownership of email addresses or phone numbers they do not control and bypass email-based or phone-based security policies. This issue is fixed in versions 3.4.11 and 4.15.1.

CWE CWE-863
Vendor zitadel
Product zitadel
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new unknown vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zitadel / zitadel
>= 2.43.0, <= 2.71.19 >= 3.0.0-rc.1, < 3.4.11 >= 4.0.0-rc.1, < 4.15.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-jq8w-8q2f-ffm9 github.com: https://github.com/zitadel/zitadel/commit/90f310212d3a5075084a603bf61fed549c92956d github.com: https://github.com/zitadel/zitadel/commit/a1748b2f0326ddf7be0de44b4f980ae2c07c0151 github.com: https://github.com/zitadel/zitadel/commit/ed09b3df7f43e870423e4d8f2757e6894481604f github.com: https://github.com/zitadel/zitadel/releases/tag/v3.4.11 github.com: https://github.com/zitadel/zitadel/releases/tag/v4.15.1