CVE-2026-29193

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton. This issue has been patched in version 4.12.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-07 15:15

Updated : 2026-03-10 17:52


NVD link : CVE-2026-29193

Mitre link : CVE-2026-29193

CVE.ORG link : CVE-2026-29193


JSON object : View

Products Affected

zitadel

  • zitadel
CWE
CWE-287

Improper Authentication