SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-54693

HIGH · CVSS 8.2 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The ZITADEL identity management platform is vulnerable in versions 2.43.0 to 2.71.19, 3.0.0 to 3.4.11, and 4.0.0 to 4.15.1, where users can exploit the email and phone self-management APIs to request verification codes without proper permissions. This flaw allows unauthorized users to claim ownership of email addresses or phone numbers, undermining email and phone-based security measures. Organizations using affected versions should prioritize upgrading to versions 3.4.11 or 4.15.1 to mitigate this security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54693
Severity
HIGH
CVSS
8.2
EPSS
0.34%

Original NVD Description

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API paths in internal/command/user_v2_email.go, internal/command/user_v2_phone.go, and internal/command/user_v2_human.go allowed users to request returned verification codes without the required permission, allowing users to claim ownership of email addresses or phone numbers they do not control and bypass email-based or phone-based security policies. This issue is fixed in versions 3.4.11 and 4.15.1.