<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T21:54:31.541976+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00674</id>
    <title>bdu:2026-00674</title>
    <updated>2026-10-07T21:54:31.615437+00:00</updated>
    <content>bdu:2026-00674</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265858</id>
    <title>EUVD-2026-265858</title>
    <updated>2026-10-07T21:54:31.615476+00:00</updated>
    <content>EUVD-2026-265858</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23511</id>
    <title>fkie_cve-2026-23511</title>
    <updated>2026-10-07T21:54:31.615491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs. This vulnerability is fixed in 4.9.1 and 3.4.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pvm5-9frx-264r</id>
    <title>GHSA-pvm5-9frx-264r — Zitadel has a user enumeration vulnerability in Login UIs</title>
    <updated>2026-10-07T21:54:31.615523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/zitadel/zitadel</p>
<p>### Summary</p>
<p>A user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and userIDs.</p>
<p>### Impact</p>
<p>The login UIs (in version 1 and 2) provide the possibility to request a password reset, where an email will be sent to the user with a link to a verification endpoint.
By submitting arbitrary userIDs to these endpoints, an attacker can differentiate between valid and invalid accounts based on the system's response.</p>
<p>For an effective exploit the attacker needs to iterate through the potential set of userIDs. The impact can be limited by implementing [rate limiting](https://zitadel.com/docs/self-hosting/manage/production#limits-and-quotas) or similar measures to limit enumeration of userIDs.</p>
<p>Additionally, Zitadel includes a security feature "Ignoring unknown usernames", designed to prevent username enumeration attacks by presenting a generic response for both valid and invalid usernames on the login page. The login UI V2 did not handle the setting correctly and would allow attackers to enumerate through usernames to check their existence.</p>
<p>### Affected Versions</p>
<p>All versions within the following ranges, including release candidates (RCs), are affected:
- **v4.x**: `4.0.0` through `4.9.0`
- **3.x**: `3.0.0` through `3.4.5`
- **2.x**: `2.0.0` through `2.71.19`</p>
<p>### Patches</p>
<p>The vulnerability has been addressed in the latest releas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pvm5-9frx-264r"/>
  </entry>
</feed>
