A high-severity authorization flaw tracked as CVE-2026-54693 allowed authenticated users of the ZITADEL identity management platform to obtain plaintext one-time verification codes during self-service profile changes. The bug affected backend authorization logic for email, phone, and human profile update paths, where multiple endpoints incorrectly hardcoded the allowSelfManagement permission flag to true. By sending profile update requests with the administrative returnCode parameter enabled, a user could receive the verification OTP directly in the JSON response instead of being required to control the target email address or phone number.
The vulnerability affects ZITADEL versions 2.43.0 through 2.71.19, 3.0.0-rc.1 through before 3.4.11, and 4.0.0-rc.1 through before 4.15.1. Security researchers said the flaw could let attackers claim ownership of email addresses or phone numbers they do not control and bypass email- or phone-based security policies. The issue is classified as CWE-863 Incorrect Authorization, is remotely exploitable, and carries a CVSS 4.0 score of 8.2. ZITADEL fixed the issue by changing the permission logic so allowSelfManagement is set dynamically to false whenever returnCode is true, with patched releases available in 3.4.11 and 4.15.1.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
ZITADEL released patched versions 3.4.11 and 4.15.1 for CVE-2026-54693. The fix changed authorization handling so self-management is no longer allowed when the administrative returnCode parameter is used.
A GitHub security advisory was published for CVE-2026-54693, describing an authorization flaw in ZITADEL that exposed verification codes during self-management API flows and could enable unauthorized email or phone ownership claims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.