{"id":"CVE-2025-64431","aliases":["GHSA-cpf4-pmr4-w6cx","GO-2025-4099"],"url":"https://o3.security/vulnerability/CVE-2025-64431","summary":"IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering","details":"### Summary\n\nZITADEL's Organization V2Beta API contains Insecure Direct Object Reference (IDOR) vulnerabilities that allow authenticated users with specific **administrator** roles within one organization to access and modify data belonging to **other** organizations.\n\n### Impact\n\nZITADEL's Organization V2Beta API, intended for managing ZITADEL organizations, contains multiple endpoints that fail to properly authorize authenticated users. An attacker with an administrator role for a specific organization could exploit this to bypass access controls and perform unauthorized actions on other organizations within the same ZITADEL instance.\n\nThis could allow an attacker to:\n\n- **Read** organization data, including the name, domains and metadata.\n- **Manipulate** (modify) the corresponding organization data.\n- **Delete** the corresponding data, up to and including the entire organization.\n\nNote that this vulnerability is limited to organization-level data (name, domains, metadata). **No other related data (such as users, projects, applications, etc.) is affected.**\n\n### Affected Versions\n\nSystems running one of the following versions are affected:\n- **v4.x**: `4.0.0-rc.1` through `4.6.2`\n\n### Patches\n\nThe vulnerability has been addressed in the latest release. The patch resolves the issue by correctly validating the caller's permission against the target organization.\n\n- v4.x: Upgrade to version [4.6.3](https://github.com/zitadel/zitadel/releases/tag/v4.6.3) or later.\n\n### Workarounds\n\nUpgrading to a patched version is the recommended solution.\n\nIf an immediate upgrade is not possible, mitigation can be achieved by disabling the affected Organization V2Beta API endpoints (e.g., /v2beta/organizations/...) at a reverse proxy or Web Application Firewall (WAF) level.\n\n### Questions\n\nIf you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)","published":"2025-11-07T18:09:25.466Z","modified":"2026-08-12T03:51:22.155312918Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/zitadel/zitadel","fixedVersion":"4.6.3"},{"ecosystem":"Go","name":"github.com/zitadel/zitadel","fixedVersion":"1.80.0-v2.20.0.20251105083648-8dcfff97ed52"}],"fix":{"url":"https://github.com/zitadel/zitadel/commit/8dcfff97ed52a8b9fc77ecb1f972744f42cff3ed","label":"zitadel/zitadel@8dcfff9"},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.6.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64431.json"},{"type":"ADVISORY","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-cpf4-pmr4-w6cx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64431"},{"type":"FIX","url":"https://github.com/zitadel/zitadel/commit/8dcfff97ed52a8b9fc77ecb1f972744f42cff3ed"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.155312918Z"}}