A vulnerability was found in Zitadel up to 2.71.19/3.4.10/4.15.0. It has been classified as critical. This affects an unknown part of the file internal/command/user_v2_email.go/internal/command/user_v2_phone.go/internal/command/user_v2_human.go of the component Email/Phone Self-Management API. The manipulation leads to permission issues.
This vulnerability is documented as CVE-2026-54693. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.