
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29193 is a login policy bypass vulnerability in Zitadel's Login V2 UI that allows unauthenticated attackers to circumvent configured security policies, including creating accounts in organizations with self-registration disabled and authenticating via login methods (e.g., username/password) that administrators have explicitly disabled. It affects Zitadel versions 4.0.0 through 4.12.0 (including RC versions) and was disclosed on March 4, 2026, with NVD publication on March 7, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, Zitadel Advisory).
The root cause is improper enforcement of login behavior and security policies in Zitadel's Login V2 UI server, classified as CWE-287 (Improper Authentication). The Login V2 UI failed to validate configured organizational policies server-side, meaning an attacker could send direct HTTP requests to login UI endpoints to trigger self-registration flows or password-based authentication flows regardless of what policies were configured. No authentication, special privileges, or user interaction is required — the attacker only needs network access to the Zitadel login UI. The fix enforces policy checks on the login UI server itself (GitHub Advisory, Zitadel Advisory).
Successful exploitation allows an unauthenticated attacker to create unauthorized user accounts in organizations that have disabled self-registration, effectively bypassing access control boundaries and gaining a foothold in the system. Additionally, attackers can authenticate using login methods (such as username/password) that administrators have disabled — for example, bypassing passwordless-only enforcement — leading to high confidentiality impact and low integrity impact. Availability is not directly affected, but unauthorized account creation and authentication could enable further lateral movement within the organization's Zitadel-managed resources (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered and responsibly disclosed by Amit Laish from GE Vernova (Zitadel Advisory).
/ui/login or organization-specific login paths in the Login V2 UI).UserAdded, UserRegistered) or authentication events (UserPasswordChecked) that contradict the organization's configured login policy settings.Zitadel has released version 4.12.1, which resolves the issue by enforcing login behavior and security policies on the Login V2 UI server. All deployments running versions 4.0.0 through 4.12.0 should upgrade to 4.12.1 or later immediately. No configuration-based workaround is available; the recommended solution is to upgrade. As an interim measure, organizations may consider implementing network-level controls to restrict access to Zitadel login endpoints to trusted networks only. Post-upgrade, administrators should audit recently created user accounts and authentication logs for signs of unauthorized activity (GitHub Advisory, Zitadel Advisory).
The vulnerability was credited to Amit Laish from GE Vernova, who responsibly disclosed it to the Zitadel security team (Zitadel Advisory). A technical write-up was published by Infinit Security covering the bypass mechanics in the Login V2 UI. An openSUSE security announcement was also issued referencing this CVE. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."