ZITADEL Authentication Bypass Cluster Exposes Self-Hosted Identity Providers
ZITADEL reports ten vulnerabilities, including seven critical flaws, that allow unauthenticated attackers to bypass authentication and take over accounts. The issues affect versions 3.x and 4.x.
**If you use ZITADEL to manage logins, update it ASAP to version 4.17.3, because ten new flaws let attackers take over accounts and bypass passwords and MFA without logging in. If you are still on version 3.x, it will never get a fix, so move to 4.x as soon as possible and check your users for unfamiliar linked logins, passkeys or authenticators.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/zitadel-authentication-bypass-cluster-exposes-self-hosted-identity-providers-x-y-t-u-q/gD2P6Ple2L