THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jq8w-8q2f-ffm9 (high) — ZITADEL Users Can Self-Verify Email/Phone via API

[GHSA] GHSA-jq8w-8q2f-ffm9 (high) — ZITADEL Users Can Self-Verify Email/Phone via API

medgithub_advisoriesPublished 2026-07-29

GHSA-jq8w-8q2f-ffm9 Severity: high CVE: CVE-2026-54693

ZITADEL Users Can Self-Verify Email/Phone via API

### Summary

A vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process.

While `GHSA-282g-fhmx-xf54` (CVE-20

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jq8w-8q2f-ffm9