Cythera Cyber Security

Zitadel Vulnerability Allows Security Control Bypass

Cythera identified a race condition in Zitadel’s password lockout policy that allows attackers to bypass account lockout safeguards, potentially exposing systems to brute-force attacks.
Talk to an expert

Introduction

Zitadel is an open-source identity platform designed to streamline identity management so developers can concentrate on core business features. Supporting B2B, B2C, and machine-to-machine (M2M) use cases, Zitadel delivers key capabilities out of the box — including hosted login, passwordless and multi-factor authentication, single sign-on (SSO), OpenID Connect, SAML, fine-grained authorisation, and a highly extensible API-driven architecture with support for custom code actions.

The Vulnerability

Cythera identified a race condition vulnerability in Zitadel’s password lockout policy feature. This flaw could allow multiple brute-force login attempts to bypass the intended lockout mechanism, enabling unauthorised access before enforcement occurs. The vulnerability was assigned a high severity score of 7.3 (CVSS) and documented under CVE-2023-47111. Zitadel responded promptly, collaborating effectively with Cythera to release a patch within a week of disclosure.

Vulnerability Discovery

During an assessment of a Zitadel deployment, Cythera uncovered a critical flaw now tracked as CVE-2023-46238. Building on that discovery, we performed additional research while preparing for his presentation at CHCon 2023 and identified another significant issue related to Zitadel’s password lockout policy.

Zitadel includes a security feature designed to lock out user accounts after a certain number of failed login attempts. However, we found that this feature could be bypassed due to a race condition—a timing issue that allows multiple login attempts to be processed before the lockout is enforced.

By sending concurrent login requests to the /ui/login/password endpoint, an attacker could exploit the window of delay before the lockout trigger activates. This meant that the intended rate-limiting protections were ineffective when requests were fired in quick succession.

The attack required no advanced tools or low-level packet manipulation. Readily available applications like Burp Suite Intruder or Turbo Intruder were enough to simulate the attack. A proof-of-concept was developed, which:-

  • Automatically generated incorrect password attempts
  • Sent them rapidly in parallel to the login endpoint

Interpreted server responses to distinguish between valid, invalid, locked-out, or successful login states using common response markers like:

  • “Password is invalid”
  • “User is locked”
  • HTTP 302 (redirect) responses indicating login success

The Results

The result demonstrated that Zitadel’s lockout mechanism could be bypassed, significantly increasing the risk of brute-force attacks.


CIO
Government Agency
Cythera operates as an extension of our team. When we call there is an immediate response and the person that answers our call is the person that resolves our issue. Cythera understands our network, and more importantly, has taken the time to understand our business. We find it easy to work with Cythera. They are approachable, flexible and have taken the time to build deep relationships with our team. It is a partnership and friendship. Cythera’s personalised, highly specialised services makes all the difference. We would recommend Cythera to anyone in the industry looking for a managed services partner.
Expert methods

We have the tools to pinpoint risks

Whether it’s hidden vulnerabilities or patterns you might miss, we help you stay one step ahead and make confident, informed decisions. Understand how our services can help your business uncover critical risks

Talk to an expert
Employee Cyber Training & Awareness
Your people are your first line of defence. Our cyber training builds awareness sharpens instincts and turns everyday staff into assets.
Advisory
When clarity is critical and stakes are high, our advisory services deliver strategic, executive-level security expertise that empowers decision-making and resilient operations.