A vulnerability labeled as problematic has been found in Zitadel up to 3.4.9/4.14.x. This impacts an unknown function. Such manipulation leads to ldap injection.
This vulnerability is referenced as CVE-2026-44671. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.