CVE-2025-53895 Details
Description
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a missing permission check. This flaw enables session hijacking, allowing an attacker to impersonate another user and access sensitive resources. Versions prior to `2.53.0` are not affected, as they required the session token for updates. Versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14 fix the issue.
A vulnerability in ZITADEL's session management API, present in versions 2.53.0 prior to 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, allows authenticated users to update sessions by knowing the session ID, due to a lack of proper permission checks. This flaw can be exploited for session hijacking, enabling an attacker to impersonate another user and access sensitive resources. Versions before 2.53.0 are not affected, as they required the session token for updates.
Users can upgrade to ZITADEL versions 4.0.0-rc.2, 3.3.2, 2.71.13, or 2.70.14. For version 4.x, ensure that users are set up correctly or require an additional role before upgrading.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zitadel zitadel | >= 2.53.0, < 2.70.14 >= 2.71.0, < 2.71.13 >= 3.0.0, < 3.3.1 4.0.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 26, 2025 | Initial Analysis | [email protected] |
| Jul 15, 2025 | New CVE Received | [email protected] |