HIGHCVSS 8.2
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Published 2026-10-04 · last modified 2026-10-04
← Get alerted the moment a CVE hits your gear — subscribe freeNcerio by BeyondNets · data from NVD, CISA KEV, EPSS.