CVE-2024-49757: Zitadel User Registration Bypass Vulnerability

Published Oct 25, 2024
·
Updated

Impact Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.63.4, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way.

Patches

2.x versions are fixed on >= 2.64.0 2.63.x versions are fixed on >= 2.63.5 2.62.x versions are fixed on >= 2.62.7 2.61.x versions are fixed on >= 2.61.4 2.60.x versions are fixed on >= 2.60.4 2.59.x versions are fixed on >= 2.59.5 2.58.x versions are fixed on >= 2.58.7

Workarounds Updating to the patched version is the recommended solution.

Questions If you have any questions or comments about this advisory, please email us at security@zitadel.com

Credits Thanks to @sevensolutions and @evilgensec for disclosing this!

Other sources

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

— MITRE

Affected Software

12 affected componentsFixes available
go/github.com/zitadel/zitadel<2.58.7
2.58.7
go/github.com/zitadel/zitadel>=2.59.0<2.59.5
2.59.5
go/github.com/zitadel/zitadel>=2.60.0<2.60.4
2.60.4
go/github.com/zitadel/zitadel>=2.61.0<2.61.4
2.61.4
go/github.com/zitadel/zitadel>=2.62.0<2.62.7
2.62.7
go/github.com/zitadel/zitadel>=2.63.0<2.63.5
2.63.5
ZITADEL ZITADEL<2.58.7
ZITADEL ZITADEL>=2.59.0<2.59.5
ZITADEL ZITADEL>=2.60.0<2.60.4
ZITADEL ZITADEL>=2.61.0<2.61.4
ZITADEL ZITADEL>=2.62.0<2.62.7
ZITADEL ZITADEL>=2.63.0<2.63.5

Event History

Oct 25, 2024
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyAffected Software
Advisory Published
via GitHub·07:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-49757?

CVE-2024-49757 is classified as a high-severity vulnerability due to unauthorized user registration capabilities.

2

How do I fix CVE-2024-49757?

To fix CVE-2024-49757, upgrade to Zitadel version 2.63.5 or later.

3

What versions of Zitadel are affected by CVE-2024-49757?

CVE-2024-49757 affects Zitadel versions prior to 2.63.4, including 2.58.7 to 2.62.7.

4

Can users still register if 'User Registration allowed' is disabled in CVE-2024-49757?

Yes, users can still register despite the option being disabled due to a missing security check in the affected versions.

5

What impact does CVE-2024-49757 have on administrator settings?

CVE-2024-49757 allows users to bypass administrative settings that disable self-registration, compromising the intended user management controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203