Improper Authentication in Zulip Server - #VU141412

 

Improper Authentication in Zulip Server - #VU141412

Published: August 11, 2026


Vulnerability identifier: #VU141412
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to authenticate as another user.

The vulnerability exists due to improper authentication in GenericOpenIdConnectBackend account lookup when processing OpenID Connect login responses. A remote user can authenticate with an unverified email claim matching another active account to authenticate as another user.

Exploitation depends on the identity provider returning an email value not actually owned by the authenticating user together with email_verified=false.


Affected software

Zulip Server

Remediation

Install security update from vendor's website.

Zulip Server - update to 12.2

External References

Related Security Bulletins