CVE-2024-49757 - CVE House
Back to Database
Status published High CVE-2024-49757

Zitadel User Registration Bypass Vulnerability

Vulnerability Description

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-49757

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zitadel
Vulnerable Versions:
>= 2.63, < 2.63.5, >= 2.62, < 2.62.7, >= 2.61, < 2.61.3, >= 2.60, < 2.60.3, >= 2.59, < 2.59.4, < 2.58.6

Timeline

Official Publish: October 25th, 2024
Last Modified: October 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)