ZITADEL SCIM API Authentication Bypass Vulnerability Allowing Unauthenticated Data Access

Vulnerability

An authentication bypass vulnerability has been identified in ZITADEL's System for Cross-domain Identity Management (SCIM) API, affecting versions 2.68.0 prior to 2.71.19, 3.0.0 prior to 3.4.7, and 4.0.0 prior to 4.12.1. The vulnerability allows unauthenticated attackers to bypass authentication and permission checks by exploiting URL-encoded path values. This exploitation enables the retrieval of sensitive user information, including names, email addresses, phone numbers, addresses, external IDs, and roles. However, due to additional data manipulation checks, attackers cannot modify or delete user data.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive user information through the SCIM API, with the potential for privacy violations and misuse of personal data.

Remediation

Users can upgrade to ZITADEL versions 3.4.8 or 4.12.2 to address this vulnerability. For those unable to upgrade, access to the SCIM API can be blocked using a reverse proxy or Web Application Firewall (WAF) rule.

Added: Mar 11, 2026, 10:37 PM
Updated: Mar 11, 2026, 10:37 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
8.3
remediation
8.3
relevance
3.8
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.