---
id: CVE-2024-32868
title: >-
  ZITADEL provides users the possibility to use Time-based One-Time-Password
  (TOTP) and One-Time-Password (OTP) through SMS and Email
summary: >-
  ZITADEL provides users the possibility to use Time-based One-Time-Password
  (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL
  already gives administrators the option to define a `Lockout Policy` with a
  maximum amount…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-297
  - CWE-307
vendor: zitadel
product: zitadel
affected:
  - zitadel < 2.50.0
patched:
  - zitadel 2.50.0
published: '2024-04-26'
updated: '2026-06-17'
sourceUpdated: '2026-06-17T07:30:35.137'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-32868'
references:
  - url: 'https://github.com/zitadel/zitadel/releases/tag/v2.50.0'
    label: security-advisories@github.com
  - url: 'https://github.com/zitadel/zitadel/security/advisories/GHSA-7j7j-66cv-m239'
    label: security-advisories@github.com
  - url: 'https://github.com/zitadel/zitadel/releases/tag/v2.50.0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/zitadel/zitadel/security/advisories/GHSA-7j7j-66cv-m239'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-08-05T16:53:50.442182Z'
ingestedAt: '2026-09-14T15:16:22.849Z'
epss: 0.00456
epssPercentile: 0.36878
---

## Overview

ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there was no such mechanism for (T)OTP checks. This issue has been patched in version 2.50.0.


## Affected

- `zitadel < 2.50.0`

## Remediation

Upgrade past the affected range:

- `zitadel 2.50.0`
