CVE-2026-29192
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-29192 is a Stored Cross-Site Scripting (XSS) vulnerability in Zitadel's Login UI (v2) that allows organization administrators to inject malicious JavaScript via the default redirect URI setting, potentially enabling account takeover of other users. The vulnerability affects Zitadel versions 4.0.0 through 4.11.1 (including RC versions) and was disclosed on March 4, 2026, with a patch released the same day. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Zitadel Advisory). The vulnerability was discovered and reported by Amit Laish from GE Vernova (GitHub Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a Stored XSS condition in Zitadel's Login UI v2 (GitHub Advisory). Zitadel permits organization administrators to configure a default redirect URI for their organization, which is used to redirect users after login; due to missing input restrictions and improper handling of this URI value, a malicious administrator can store a JavaScript payload that executes in the browsers of users who subsequently log in through the affected login UI (Zitadel Advisory). The attack requires the attacker to hold organization administrator privileges to set the malicious redirect URI, but once stored, exploitation is passive — any user logging in via the affected organization's login flow is exposed without further interaction. A secondary exploitation path involves using the XSS to trigger a password reset for the victim, bypassing the need for the current password (a behavior also corrected in the patch) (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker (leveraging a malicious organization admin's stored payload) to execute arbitrary JavaScript in victims' browsers within the Zitadel login UI context, enabling session hijacking, credential theft, and full account takeover via forced password reset (GitHub Advisory). Both confidentiality and integrity are rated High, as attackers can access sensitive user data and modify account credentials; availability is not directly impacted. Accounts protected by Multi-Factor Authentication (MFA) or Passwordless authentication are not susceptible to the account takeover vector, as the attack relies on password reset functionality (Zitadel Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to first obtain organization administrator privileges within a Zitadel instance, which raises the practical bar for opportunistic attackers, though insider threats or compromised admin accounts remain a realistic vector.

Exploitation steps

  1. Obtain Organization Admin Access: Gain organization administrator privileges within a target Zitadel instance (e.g., through credential compromise, social engineering, or a pre-existing admin account).
  2. Configure Malicious Redirect URI: Navigate to the organization settings in Zitadel and set the default redirect URI to a value containing a malicious JavaScript payload (e.g., a javascript: URI or a crafted URL that injects script content into the login UI v2 page).
  3. Wait for Victim Login: The stored payload is now associated with the organization's login flow. When any user in the organization logs in via the Zitadel Login UI v2, the malicious JavaScript executes in their browser.
  4. Execute Payload: The injected script can steal session tokens, cookies, or other credentials, or silently initiate a password reset for the victim's account (exploiting the pre-patch behavior that did not require the current password during certain session states).
  5. Account Takeover: Using the reset password or stolen session, the attacker gains full control of the victim's account (GitHub Advisory, Zitadel Advisory).

Indicators of compromise

  • Logs: Zitadel audit logs showing unexpected changes to the organization's default redirect URI, particularly to values containing javascript:, encoded script tags, or unusual URL schemes.
  • Logs: Password reset events for user accounts that were not initiated by the account owner, especially in bulk or in rapid succession.
  • Network: Outbound requests from users' browsers to unexpected external domains shortly after login, potentially indicating data exfiltration by injected scripts.
  • Application: Zitadel admin activity logs showing organization configuration changes by accounts not recognized as legitimate administrators.

Mitigation and workarounds

Zitadel has addressed the vulnerability in version 4.12.0, which prevents execution of malicious code in the login UI and additionally requires the user's current password on the password change page regardless of session state (GitHub Advisory). All users running Zitadel 4.0.0 through 4.11.1 should upgrade to version 4.12.0 or later immediately. As an interim risk reduction measure (not a full workaround), enforcing MFA or Passwordless authentication for all users will mitigate the account takeover vector, though the XSS itself remains exploitable until patching (Zitadel Advisory). Questions can be directed to security@zitadel.com.

Community reactions

The vulnerability was reported by Amit Laish from GE Vernova, and Zitadel publicly credited the researcher in their advisory (Zitadel Advisory). A technical write-up was published at infinitsec.net shortly after disclosure, and the vulnerability received coverage on social platforms including Mastodon and Bluesky (Feedly). OpenSUSE also issued a security announcement referencing the advisory (openSUSE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management