
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64717 is an improper authentication vulnerability in ZITADEL, an open-source identity management platform, that allows unauthenticated attackers to perform account takeover by exploiting a flaw in the federation/auto-linking process. The vulnerability was disclosed on November 12–13, 2025, and affects ZITADEL versions 2.50.0–2.71.18, 3.0.0–3.4.3, and 4.0.0–4.6.5. It was reported by Jan Kühnlein of kultify and patched on November 12, 2025 (GitHub Advisory). The CVSS v3.1 base score is 9.8 (Critical), while the CNA-assigned CVSS v4.0 base score is 7.4 (High) (GitHub Advisory, Feedly).
The root cause is classified as CWE-287 (Improper Authentication): ZITADEL's federation process failed to correctly validate an organization's login policy — specifically, whether a given Identity Provider (IdP) was active and whether the organization permitted federated authentication — before executing the auto-linking step (GitHub Advisory). An unauthenticated attacker can initiate a login flow using an instance-level IdP that has been explicitly disabled for a target organization; the platform incorrectly accepts the external identity and, based on matching criteria (e.g., email address), links it to an existing internal user account, effectively granting the attacker access to that account (GitHub Advisory). Two key preconditions limit the attack surface: the targeted account must not have MFA enabled, and the exploited IdP must be registered at the instance level (not at another organization level) (GitHub Advisory). The fix, introduced in commit 33c51deb20402dd5720e32cfb0c1d5fdc752f2e0, correctly enforces the organization's login policy prior to any auto-linking action (Feedly).
Successful exploitation results in full account takeover of any non-MFA-protected user account within an affected ZITADEL organization, granting the attacker complete control over the victim's identity, including access to all resources, applications, and data the account is authorized to reach (GitHub Advisory). The confidentiality and integrity of the compromised account are fully undermined, though availability is not directly impacted. Because ZITADEL functions as a central identity provider, a compromised account could serve as a pivot point for lateral movement into downstream applications and services that rely on ZITADEL for authentication (Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.34%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Despite the lack of active exploitation, the unauthenticated nature of the attack and the critical CVSS v3.1 score make it a high-priority patching target for organizations running affected ZITADEL versions without universal MFA enforcement.
idp.user.linked or equivalent federation events in the audit trail./idps/callback) from unexpected IP addresses or geographic locations, particularly for accounts not recently active.The primary and only recommended remediation is to upgrade ZITADEL to a patched version: v2.71.19 (for v2.x), v3.4.4 (for v3.x), or v4.6.6 (for v4.x) (GitHub Advisory, v2.71.19 Release, v3.4.4 Release, v4.6.6 Release). No configuration-based workarounds are available aside from upgrading. As an interim risk-reduction measure, enabling MFA for all user accounts will prevent account takeover via this vulnerability, since MFA-protected accounts are not susceptible to this attack (GitHub Advisory). Organizations should also audit their instance-level IdP configurations and review audit logs for any suspicious auto-linking events.
The vulnerability was noted by security community accounts on Mastodon (infosec.exchange) and Bluesky shortly after disclosure, reflecting routine community monitoring of identity platform CVEs (Feedly). Red Hat published a security advisory tracking the CVE, and INCIBE (Spain's national cybersecurity agency) issued an early warning alert (Feedly). No significant vendor statements beyond the ZITADEL security advisory, nor notable researcher deep-dives or media coverage, have been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."