CVE-2026-32132: ZITADEL: Reactivation of Expired Passkey Registration Codes
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new passkey using a previously retrieved code. An improper expiration check of the code, could allow an attacker to potentially register their own passkey and gain access to the victim's account. This vulnerability is fixed in 3.4.8 and 4.12.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32132?
CVE-2026-32132 is rated as a medium severity vulnerability that can potentially allow the reactivation of expired passkey registration codes.
How do I fix CVE-2026-32132?
To address CVE-2026-32132, upgrade your ZITADEL software to version 3.4.8 or later, or version 4.12.2 or later.
Which versions of ZITADEL are affected by CVE-2026-32132?
CVE-2026-32132 affects ZITADEL versions prior to 3.4.8 and 4.12.2.
What type of vulnerability is CVE-2026-32132?
CVE-2026-32132 is a security vulnerability related to the registration of passkeys in ZITADEL.
Can CVE-2026-32132 be exploited remotely?
Yes, CVE-2026-32132 can potentially be exploited remotely by an attacker accessing the affected endpoints.