CVE-2026-32130 Details
Description
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with URL-encoded path values were correctly routed but would bypass necessary authentication and permission checks. This allowed unauthenticated attackers to retrieve sensitive information such as names, email addresses, phone numbers, addresses, external IDs, and roles. Note that due to additional checks when manipulating data, an attacker could not modify or delete any user data. This vulnerability is fixed in 3.4.8 and 4.12.2.
An authentication bypass vulnerability has been identified in ZITADEL's System for Cross-domain Identity Management (SCIM) API, affecting versions 2.68.0 prior to 2.71.19, 3.0.0 prior to 3.4.7, and 4.0.0 prior to 4.12.1. The vulnerability allows unauthenticated attackers to bypass authentication and permission checks by exploiting URL-encoded path values. This exploitation enables the retrieval of sensitive user information, including names, email addresses, phone numbers, addresses, external IDs, and roles. However, due to additional data manipulation checks, attackers cannot modify or delete user data.
Users can upgrade to ZITADEL versions 3.4.8 or 4.12.2 to address this vulnerability. For those unable to upgrade, access to the SCIM API can be blocked using a reverse proxy or Web Application Firewall (WAF) rule.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zitadel zitadel | >= 2.68.0, < 3.4.8 >= 4.0.0, < 4.12.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | Initial Analysis | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |