CVE-2026-29193
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-29193 is a login policy bypass vulnerability in Zitadel's Login V2 UI that allows unauthenticated attackers to circumvent configured security policies, including creating accounts in organizations with self-registration disabled and authenticating via login methods (e.g., username/password) that administrators have explicitly disabled. It affects Zitadel versions 4.0.0 through 4.12.0 (including RC versions) and was disclosed on March 4, 2026, with NVD publication on March 7, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, Zitadel Advisory).

Technical details

The root cause is improper enforcement of login behavior and security policies in Zitadel's Login V2 UI server, classified as CWE-287 (Improper Authentication). The Login V2 UI failed to validate configured organizational policies server-side, meaning an attacker could send direct HTTP requests to login UI endpoints to trigger self-registration flows or password-based authentication flows regardless of what policies were configured. No authentication, special privileges, or user interaction is required — the attacker only needs network access to the Zitadel login UI. The fix enforces policy checks on the login UI server itself (GitHub Advisory, Zitadel Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to create unauthorized user accounts in organizations that have disabled self-registration, effectively bypassing access control boundaries and gaining a foothold in the system. Additionally, attackers can authenticate using login methods (such as username/password) that administrators have disabled — for example, bypassing passwordless-only enforcement — leading to high confidentiality impact and low integrity impact. Availability is not directly affected, but unauthorized account creation and authentication could enable further lateral movement within the organization's Zitadel-managed resources (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and responsibly disclosed by Amit Laish from GE Vernova (Zitadel Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Zitadel instances running versions 4.0.0–4.12.0 by examining HTTP response headers, login page branding, or version disclosure endpoints.
  2. Identify target organization: Determine the target organization's login URL within the Zitadel instance (e.g., /ui/login or organization-specific login paths in the Login V2 UI).
  3. Bypass self-registration policy: Send a direct HTTP POST request to the Login V2 UI's registration endpoint, bypassing the UI flow that would normally enforce the organization's self-registration restriction. The server fails to validate the policy, allowing account creation to proceed.
  4. Bypass authentication method policy: Alternatively, send a direct HTTP POST request to the Login V2 UI's password authentication endpoint even when the organization enforces passwordless-only login. The server does not enforce the policy restriction, allowing password-based authentication.
  5. Gain unauthorized access: Use the newly created account or the bypassed authentication method to log in and access resources within the organization, potentially enabling further lateral movement (GitHub Advisory, Zitadel Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to Zitadel Login V2 UI registration or authentication endpoints from external or unknown IP addresses, particularly when self-registration or password login is disabled in policy.
  • Logs: Zitadel application logs showing successful user registrations in organizations with self-registration disabled; successful password-based authentication events in organizations enforcing passwordless-only policies.
  • Application Events: New user accounts created in organizations where self-registration is administratively disabled; authentication events using login methods inconsistent with the configured security policy.
  • Audit Trail: Review Zitadel audit logs for account creation events (UserAdded, UserRegistered) or authentication events (UserPasswordChecked) that contradict the organization's configured login policy settings.

Mitigation and workarounds

Zitadel has released version 4.12.1, which resolves the issue by enforcing login behavior and security policies on the Login V2 UI server. All deployments running versions 4.0.0 through 4.12.0 should upgrade to 4.12.1 or later immediately. No configuration-based workaround is available; the recommended solution is to upgrade. As an interim measure, organizations may consider implementing network-level controls to restrict access to Zitadel login endpoints to trusted networks only. Post-upgrade, administrators should audit recently created user accounts and authentication logs for signs of unauthorized activity (GitHub Advisory, Zitadel Advisory).

Community reactions

The vulnerability was credited to Amit Laish from GE Vernova, who responsibly disclosed it to the Zitadel security team (Zitadel Advisory). A technical write-up was published by Infinit Security covering the bypass mechanics in the Login V2 UI. An openSUSE security announcement was also issued referencing this CVE. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability tracking and aggregation sites.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management