CVE-2025-53895: Zitadel
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a missing permission check. This flaw enables session hijacking, allowing an attacker to impersonate another user and access sensitive resources. Versions prior to `2.53.0` are not affected, as they required the session token for updates. Versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14 fix the issue.
Affected products
- Zitadel Zitadel: from 2.53.0, before 2.70.14 (fixed in 2.70.14); from 2.71.0, before 2.71.13 (fixed in 2.71.13); from 3.0.0, before 3.3.1 (fixed in 3.3.1); version 4.0.0 only
Published 2025-07-15. Last modified 2026-06-17.