{"id":"CVE-2025-53895","summary":"ZITADEL has broken authN and authZ in session API and resulting session tokens","details":"ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a missing permission check. This flaw enables session hijacking, allowing an attacker to impersonate another user and access sensitive resources. Versions prior to `2.53.0` are not affected, as they required the session token for updates. Versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14 fix the issue.","aliases":["GHSA-6c5p-6www-pcmr"],"modified":"2026-08-12T03:51:21.073634626Z","published":"2025-07-15T16:39:00.635Z","database_specific":{"cwe_ids":["CWE-384","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53895.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v2.70.14"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v2.71.13"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v3.3.2"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.0.0-rc.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53895.json"},{"type":"ADVISORY","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-6c5p-6www-pcmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53895"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zitadel/zitadel","events":[{"introduced":"8ce3af2f9d7cc763ac9c72a038a7f3218259f062"},{"fixed":"6cf453f8f759fdec10764a6a815111ad74bcf92c"},{"introduced":"bc019a3447b40bb62193b98d80c1103410845bd0"},{"fixed":"17f033f0b4d27bb45fc24acfb0b0573914896297"},{"introduced":"573c96d6af6aa8778efd9bff59f9bc0dab94c495"},{"fixed":"c787cdf7b4bda5ff28b8144b9fbb1a60730116c2"},{"fixed":"b76d8d37cbc6da7e062648083d80c03a7d89c6cd"},{"fixed":"40094bee873cc2dbb96d63ff4605751841f97a22"}],"database_specific":{"cpe":"cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.53.0"},{"fixed":"2.70.14"},{"introduced":"2.71.0"},{"fixed":"2.71.13"},{"introduced":"3.0.0"},{"fixed":"3.3.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["= 4.0.0-rc.1","v4.0.0-rc.1","v2.70.13","v2.71.12","v3.3.1","v3.3.0","v3.2.3","v3.2.2","v2.71.11","v2.70.12","v3.2.1","v3.2.0","v3.1.0","v3.0.4","v2.71.10","v2.70.11","v3.0.3","v2.70.10","v2.71.9","v3.0.2","v3.0.1","v3.0.0","v2.71.8","v2.70.9","v2.71.7","v2.70.8","v2.71.6","v2.70.7","v2.71.5","v2.70.6","v2.71.4","v2.70.5","v2.71.3","v2.70.4","v2.71.2","v2.70.3","v2.71.1","v2.70.2","v2.70.1","v2.71.0","v2.70.0","v2.69.3","v2.69.2","v2.69.1","v2.69.0","v2.68.1","v2.67.4","v2.68.0","v2.67.3","v2.67.2","v2.67.1","v2.67.0","v2.66.3","v2.66.2","v2.66.1","v2.66.0","v2.65.4","v2.65.3","v2.65.2","v2.65.1","v2.65.0","v2.64.1","v2.64.0","v2.63.4","v2.63.3","v2.63.2","v2.63.1","v2.63.0","v2.62.3","v2.62.2","v2.62.1","v2.62.0","v2.61.0","v2.59.1","v2.60.0","v2.58.3","v2.59.0","v2.58.2","v2.58.1","v2.56.1","v2.58.0","v2.57.0","v2.56.0","v2.55.2","v2.55.1","v2.55.0","v2.54.3","v2.54.2","v2.54.1","v2.54.0","v2.53.2","v2.53.1","v2.53.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53895.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}