Skip to main content
Vulnerability Database/CVE-2025-67717

CVE-2025-67717: Zitadel Information Disclosure Vulnerability

CVE-2025-67717 is an information disclosure vulnerability in Zitadel that exposes total user counts to authenticated users regardless of permissions. This article covers technical details, affected versions, and patches.

Published:

CVE-2025-67717 Overview

CVE-2025-67717 is an information disclosure vulnerability in ZITADEL, an open-source identity infrastructure platform. Affected versions expose the total number of instance users to any authenticated user through the totalResult field, regardless of that user's assigned permissions. The flaw does not leak individual user records or personally identifiable information (PII), but the aggregate user count itself may be sensitive in multi-tenant or regulated deployments. The issue affects ZITADEL versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1, and is categorized under [CWE-497] Exposure of Sensitive System Information to an Unauthorized Control Sphere. Fixed builds are available in 3.4.5 and 4.7.2.

Critical Impact

Any authenticated ZITADEL user, including low-privilege accounts, can enumerate the total user count of an instance, enabling reconnaissance against identity infrastructure.

Affected Products

  • ZITADEL versions 2.44.0 through 3.4.4
  • ZITADEL versions 4.0.0-rc.1 through 4.7.1
  • Self-hosted and cloud deployments of the affected zitadel/zitadel releases

Discovery Timeline

  • 2025-12-11 - CVE-2025-67717 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-67717

Vulnerability Analysis

ZITADEL exposes user query endpoints that return a paginated result set along with a totalResult field describing the full count of matching records. In vulnerable releases, permission checks are applied to the returned user objects but not to the aggregate counter. An authenticated caller therefore receives an accurate total even when authorization would otherwise filter every individual record from the response.

The issue is classified as [CWE-497], sensitive system information disclosure. While no PII is returned, the total user count is a useful reconnaissance signal for attackers assessing the scale of an identity tenant, planning credential stuffing, or profiling a target organization.

Root Cause

The root cause is missing authorization enforcement on the aggregate result counter in the user query path implemented in internal/query/user.go. Result-level filtering was applied to the returned rows, but the total count was computed and returned before permission scoping was enforced. The upstream fix is delivered in commit 826039c6208fe71df57b3a94c982b5ac5b0af12c.

Attack Vector

Exploitation requires only network access to the ZITADEL API and valid low-privilege credentials. An authenticated user issues a standard user list or search request and reads the totalResult field from the response. No elevated role, tenant admin permission, or user interaction is required.

go
// Patch excerpt from internal/query/user.go
 	"database/sql"
 	_ "embed"
 	"errors"
-	"slices"
 	"strings"
 	"time"

Source: ZITADEL commit 826039c. The commit removes the now-unused slices import as part of refactoring the user query logic so that the total count reflects only records the caller is authorized to see.

Detection Methods for CVE-2025-67717

Indicators of Compromise

  • Repeated authenticated calls to ZITADEL user list or search endpoints from a single principal within short time windows.
  • API responses where callers read the totalResult field but retrieve zero or few user records, indicating count-only enumeration.
  • Low-privilege service accounts or newly provisioned users querying user directories they have no functional need to access.

Detection Strategies

  • Enable ZITADEL audit logging for user query APIs and forward events to a centralized log platform for correlation.
  • Baseline normal query volume per principal and alert on statistically anomalous access to user enumeration endpoints.
  • Review access logs after upgrade to identify accounts that queried user counts while running vulnerable versions 2.44.0 through 3.4.4 or 4.0.0-rc.1 through 4.7.1.

Monitoring Recommendations

  • Ingest ZITADEL application and reverse-proxy logs into a SIEM or data lake and retain them for behavioral analysis.
  • Alert on low-privilege principals issuing bulk paginated queries against user objects.
  • Monitor for reconnaissance patterns that combine identity enumeration with subsequent authentication attempts against enumerated tenants.

How to Mitigate CVE-2025-67717

Immediate Actions Required

  • Upgrade ZITADEL to version 3.4.5 or 4.7.2, which contain the authorization fix for the totalResult field.
  • Inventory all self-hosted ZITADEL deployments and confirm running versions against the affected ranges.
  • Rotate or review low-privilege API credentials that may have been used to enumerate user counts prior to patching.

Patch Information

The vendor released fixes in ZITADEL 3.4.5 and 4.7.2. The corrective change is documented in GitHub Security Advisory GHSA-f4cf-9rvr-2rcx and implemented in ZITADEL commit 826039c. Operators should follow the standard ZITADEL upgrade procedure and validate that user query responses no longer disclose counts outside the caller's authorization scope.

Workarounds

  • Restrict network exposure of the ZITADEL management API to trusted networks or VPN clients until patching completes.
  • Reduce the number of low-privilege accounts able to authenticate to the API and enforce short-lived tokens.
  • Apply reverse-proxy rate limiting to user query endpoints to slow enumeration attempts.
bash
# Example: verify installed ZITADEL version before and after upgrade
zitadel --version

# Container example: pin to a patched release
docker pull ghcr.io/zitadel/zitadel:v4.7.2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.