CVE-2026-32131 Details
Description
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant.read, or project.app.read) to retrieve management-plane information belonging to other organizations by specifying a different tenant’s project_id, grant_id, or app_id. This vulnerability is fixed in 3.4.8 and 4.12.2.
A cross-tenant information disclosure vulnerability has been identified in ZITADEL's Management API, affecting versions 4.0.0 prior to 4.12.2, 3.0.0 prior to 3.4.8, and 2.0.0 prior to 2.71.19. This vulnerability allows authenticated users with low-privilege tokens to access management-plane information from other organizations by manipulating project, grant, or app identifiers. The issue arises from insufficient validation of resource ownership, enabling unauthorized data access across tenants.
Users can upgrade to ZITADEL versions 4.12.2 or 3.4.8 to address this vulnerability. For version 2.x, updating to 3.4.8 is recommended. If an upgrade is not feasible and the Management V1 API is no longer in use, access can be blocked through a reverse proxy or WAF rule.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zitadel zitadel | < 3.4.8 >= 4.0.0, < 4.12.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | Initial Analysis | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |