VDB

ANCHORE-2026-29191

ANCHORE-2026-29191 PUBLISHED

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

Affected Products

VendorProductVersions
zitadelzitadel4.0.0, 4.0.0, 4.0.0

Timeline

  • Mar 7, 2026 CVE Published
  • Mar 7, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›