cognitive cybersecurity intelligence

News and Analysis

Search

ZITADEL IDOR Vulnerabilities Let Attackers Modify Sensitive Settings

A critical IDOR vulnerability (CVE-2025-27507) in ZITADEL’s Admin API exposes organizations to account takeover risks, allowing low-privilege users to manipulate sensitive settings. Rated 9.0/10 on the CVSS scale, attackers can reroute LDAP authentication, extract credentials, or deploy phishing. ZITADEL has released patches; organizations must upgrade and audit configurations to mitigate risks.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts