CVE-2025-67717 - CVE House
Back to Database
Status published Medium CVE-2025-67717

Zitadel Discloses the Total Number of Instance Users

Vulnerability Description

ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, regardless of their specific permissions. While this does not leak individual user data or PII, disclosing the total user count via the totalResult field constitutes an information disclosure vulnerability that may be sensitive in certain contexts. This issue is fixed in versions 3.4.5 and 4.7.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67717

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zitadel
Vulnerable Versions:
< 1.80.0-v2.20.0.20251210, >= 2.44.0, < 3.4.5, >= 4.0.0-rc.1, < 4.7.2

Timeline

Official Publish: December 11th, 2025
Last Modified: December 11th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)