cognitive cybersecurity intelligence

News and Analysis

Search

ZITADEL IDOR Vulnerabilities Let Attackers Modify Sensitive Settings

A critical IDOR vulnerability (CVE-2025-27507) in ZITADEL’s Admin API exposes organizations to account takeover risks, allowing low-privilege users to manipulate sensitive settings. Rated 9.0/10 on the CVSS scale, attackers can reroute LDAP authentication, extract credentials, or deploy phishing. ZITADEL has released patches; organizations must upgrade and audit configurations to mitigate risks.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Expanded BadBox botnet partly disrupted

The BadBox 2.0 malware botnet operation has been partially dismantled, affecting over 1 million Android devices worldwide. The joint operation, led by HUMAN’s Satori Threat