
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29192 is a Stored Cross-Site Scripting (XSS) vulnerability in Zitadel's Login UI (v2) that allows organization administrators to inject malicious JavaScript via the default redirect URI setting, potentially enabling account takeover of other users. The vulnerability affects Zitadel versions 4.0.0 through 4.11.1 (including RC versions) and was disclosed on March 4, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Zitadel Advisory). The vulnerability was discovered and reported by Amit Laish from GE Vernova (GitHub Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS condition in Zitadel's Login UI v2 (GitHub Advisory). Zitadel permits organization administrators to configure a default redirect URI for their organization, which is used to redirect users after login; due to missing input restrictions and improper handling of this URI value, a malicious administrator can store a JavaScript payload that executes in the browsers of users who subsequently log in through the affected login UI (Zitadel Advisory). The attack requires the attacker to hold organization administrator privileges to set the malicious redirect URI, but once stored, exploitation is passive — any user logging in via the affected organization's login flow is exposed without further interaction. A secondary exploitation path involves using the XSS to trigger a password reset for the victim, bypassing the need for the current password (a behavior also corrected in the patch) (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker (leveraging a malicious organization admin's stored payload) to execute arbitrary JavaScript in victims' browsers within the Zitadel login UI context, enabling session hijacking, credential theft, and full account takeover via forced password reset (GitHub Advisory). Both confidentiality and integrity are rated High, as attackers can access sensitive user data and modify account credentials; availability is not directly impacted. Accounts protected by Multi-Factor Authentication (MFA) or Passwordless authentication are not susceptible to the account takeover vector, as the attack relies on password reset functionality (Zitadel Advisory).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to first obtain organization administrator privileges within a Zitadel instance, which raises the practical bar for opportunistic attackers, though insider threats or compromised admin accounts remain a realistic vector.
javascript: URI or a crafted URL that injects script content into the login UI v2 page).javascript:, encoded script tags, or unusual URL schemes.Zitadel has addressed the vulnerability in version 4.12.0, which prevents execution of malicious code in the login UI and additionally requires the user's current password on the password change page regardless of session state (GitHub Advisory). All users running Zitadel 4.0.0 through 4.11.1 should upgrade to version 4.12.0 or later immediately. As an interim risk reduction measure (not a full workaround), enforcing MFA or Passwordless authentication for all users will mitigate the account takeover vector, though the XSS itself remains exploitable until patching (Zitadel Advisory). Questions can be directed to security@zitadel.com.
The vulnerability was reported by Amit Laish from GE Vernova, and Zitadel publicly credited the researcher in their advisory (Zitadel Advisory). A technical write-up was published at infinitsec.net shortly after disclosure, and the vulnerability received coverage on social platforms including Mastodon and Bluesky (Feedly). OpenSUSE also issued a security announcement referencing the advisory (openSUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."