ZITADEL faced a critical Insecure Direct Object Reference (IDOR) vulnerability (CVE-2025-27507), threatening organizations through account takeover and configuration tampering risks. Authenticated users with low privilege were able to manipulate LDAP authentication settings, resulting in potential full account compromise and backend directory infrastructure exposure. Attackers could exploit vulnerable endpoints to reroute LDAP authentication, extract service credentials, deploy phishing content, and disable MFA controls. The exploitation was hard to detect due to minimal forensic traces, posing significant security challenges. Prompt patching and auditing were required to mitigate risks.
Source: https://cybersecuritynews.com/zitadel-idor-vulnerabilities/
"id": "zit404030625",
"linkid": "zitadel",
"type": "Vulnerability",
"date": "3/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"