{"id":"GHSA-cpf4-pmr4-w6cx","summary":"IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering","details":"### Summary\n\nZITADEL's Organization V2Beta API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users with specific **administrator** roles within one organization to access and modify data belonging to **other** organizations.\n\n### Impact\n\nZITADEL's Organization V2Beta API, intended for managing ZITADEL organizations, contains multiple endpoints that fail to properly authorize authenticated users. An attacker with an administrator role for a specific organization could exploit this to bypass access controls and perform unauthorized actions on other organizations within the same ZITADEL instance.\n\nThis could allow an attacker to:\n\n- **Read** organization data, including the name, domains and metadata.\n- **Manipulate** (modify) the corresponding organization data.\n- **Delete** the corresponding data, up to and including the entire organization.\n\nNote that this vulnerability is limited to organization-level data (name, domains, metadata). **No other related data (such as users, projects, applications, etc.) is affected.**\n\n### Affected Versions\n\nSystems running one of the following versions are affected:\n- **v4.x**: `4.0.0-rc.1` through `4.6.2`\n\n### Patches\n\nThe vulnerability has been addressed in the latest release. The patch resolves the issue by correctly validating the caller's permission against the target organization.\n\n- v4.x: Upgrade to version [4.6.3](https://github.com/zitadel/zitadel/releases/tag/v4.6.3) or later.\n\n### Workarounds\n\nUpgrading to a patched version is the recommended solution.\n\nIf an immediate upgrade is not possible, mitigation can be achieved by disabling the affected Organization V2Beta API endpoints (e.g., /v2beta/organizations/...) at a reverse proxy or Web Application Firewall (WAF) level.\n\n### Questions\n\nIf you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)","aliases":["CVE-2025-64431","GO-2025-4099"],"modified":"2025-11-17T19:42:36.607523Z","published":"2025-11-05T19:52:01Z","database_specific":{"github_reviewed_at":"2025-11-05T19:52:01Z","nvd_published_at":"2025-11-07T19:16:26Z","cwe_ids":["CWE-639"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-cpf4-pmr4-w6cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64431"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/commit/8dcfff97ed52a8b9fc77ecb1f972744f42cff3ed"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.6.3"}],"affected":[{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-rc.1"},{"fixed":"4.6.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 4.6.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-cpf4-pmr4-w6cx/GHSA-cpf4-pmr4-w6cx.json"}},{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.80.0-v2.20.0.20250414095945-f365cee73242"},{"fixed":"1.80.0-v2.20.0.20251105083648-8dcfff97ed52"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-cpf4-pmr4-w6cx/GHSA-cpf4-pmr4-w6cx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}