CVE-2025-53895
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a missing permission check. This flaw enables session hijacking, allowing an attacker to impersonate another user and access sensitive resources. Versions prior to `2.53.0` are not affected, as they required the session token for updates. Versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14 fix the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.35%
- CWE
- CWE-863, CWE-384
- Published
- 2025-07-15
- Last modified
- 2026-03-13
Affected products
- zitadel zitadel
- zitadel zitadel
- zitadel zitadel
- zitadel zitadel
Weakness type
Related vulnerabilities
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-87014 — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
- CVE-2026-46460 — Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and...
- CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
- CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
- CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
- CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients