{"schema_version":"1.7.3","id":"GHSA-25rw-g6ff-fmg8","published":"2026-03-04T22:51:16Z","modified":"2026-03-23T04:56:19.304930173Z","aliases":["CVE-2026-29193","GO-2026-4604"],"summary":"ZITADEL: Login V2 UI Policy Bypass Allows Unauthorized Self-Registration and Authentication","details":"### Summary\n\nA vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their organizaton.\n\n### Impact\n\nZitadel enables administrators to configure their organization’s login behavior and security policies. As part of this functionality, they can disable user self-registration, enforce passwordless logins only, and more.\n\nDue to improper enforcement an attacker could send direct HTTP requests to the login UI and create accounts in organizations that have disabled user self-registration, and gain unauthorized access to the system.\nThe same attack vector could be used to authenticate for example using username and password even when this login method was disabled.\n\n### Affected Versions\n\nSystems running one of the following versions are affected:\n- **4.x**: `4.0.0` through `4.12.0` (including RC versions)\n\n### Patches\n\nThe vulnerability has been addressed in the latest releases. The patch resolves the issue by enforcing the policies on the logiin UI server.\n\n4.x: Upgrade to >=[4.12.1](https://github.com/zitadel/zitadel/releases/tag/v4.12.1)\n\n### Workarounds\n\nThe recommended solution is to upgrade to a patched version.\n\n### Questions\n\nIf there are any questions or comments about this advisory, please send an email to [security@zitadel.com](mailto:security@zitadel.com)\n\n### Credits \n\nZITADEL extends thanks once again to Amit Laish from GE Vernova for finding and reporting the vulnerability.","affected":[{"package":{"name":"github.com/zitadel/zitadel/v2","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.12.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.12.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-25rw-g6ff-fmg8/GHSA-25rw-g6ff-fmg8.json"}},{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.12.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 4.12.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-25rw-g6ff-fmg8/GHSA-25rw-g6ff-fmg8.json"}}],"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-25rw-g6ff-fmg8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29193"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.12.1"}],"database_specific":{"cwe_ids":["CWE-287"],"github_reviewed":true,"github_reviewed_at":"2026-03-04T22:51:16Z","nvd_published_at":"2026-03-07T15:15:55Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}