CVE-2026-105206

CVE-2026-105206 published: ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member hold...

View full NVD advisory → ← Back to CVE watch