A critical IDOR vulnerability (CVE-2025-27507) in ZITADEL’s Admin API exposes organizations to account takeover risks, allowing low-privilege users to manipulate sensitive settings. Rated 9.0/10 on the CVSS scale, attackers can reroute LDAP authentication, extract credentials, or deploy phishing. ZITADEL has released patches; organizations must upgrade and audit configurations to mitigate risks.

Providers must create smarter, more connected healthcare environments, tech CEO says
Sandy Saggar, CEO of Connexall, emphasized at HIMSS25 that effective health IT transcends technology, focusing on vendor-neutral interoperability to enhance patient care and streamline workflows.