CVE-2024-32868Medium· 6.5▾ SunlitZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a Lockout Policy with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks. This issue has been patched in version 2.50.0.
zitadel < 2.50.0Upgrade past the affected range:
zitadel 2.50.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56666Medium· 4.8ZITADEL is an open source identity management platform
CVE-2026-76081Medium· 5.5ZITADEL is an open source identity management platform
CVE-2026-46649Critical· 9.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks
CVE-2026-58271Medium· 6.8Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing
CVE-2026-91166Medium· 5.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux
CVE-2026-77561Medium· 5.3Tinyauth is an authentication and authorization server