CVE-2026-29191
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.
CRITICAL · CVSS 9.3
EPSS 0.00018
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0