A AegiFlow
HIGHCVSS 8.2EPSS 0.3%

CVE-2026-54693

CVE-2026-54693 updated by NVD

Published
2026-07-29
Modified
2026-07-31
EPSS percentile
27%
Sources
github-advisory, nvd

Summary

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to request returned verification codes without the required permission, allowing users to claim ownership of email addresses or phone numbers they do not control and bypass email-based or phone-based security policies. This issue is fixed in versions 3.4.11 and 4.15.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/zitadel/zitadel1.80.0-v2.20.0.20260608144108-ed09b3df7f43

Remediation: Upgrade to 1.80.0-v2.20.0.20260608144108-ed09b3df7f43 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.