{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-85057/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-85057"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZITADEL (3.0.0 through 3.4.12)","ZITADEL (4.0.0 through 4.16.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","sandbox-escape","zitadel","cve-2026-85057"],"_cs_type":"advisory","_cs_vendors":["ZITADEL"],"content_html":"\u003cp\u003eZITADEL versions 3.x (\u0026lt; 3.4.13) and 4.x (\u0026lt; 4.16.1) contain a high-severity vulnerability (CVE-2026-85057) that enables a sandbox escape from the ZITADEL Actions V1 environment. Actions in ZITADEL are triggered during OIDC, SAML, and login flows, executing custom JavaScript within the server process using the goja Node-compatible engine.\u003c/p\u003e\n\u003cp\u003eThe vulnerability stems from the engine's \u003ccode\u003erequire()\u003c/code\u003e module loader, which was improperly configured to allow loading files from the host filesystem rather than restricting imports to authorized \u003ccode\u003ezitadel/*\u003c/code\u003e modules. Because the ZITADEL process must have read access to certain configuration files and secrets to function, an attacker with \u003ccode\u003eorg.action.write\u003c/code\u003e or \u003ccode\u003eorg.flow.write\u003c/code\u003e permissions (typically held by an ORG_OWNER) can craft malicious scripts to read these files. This is particularly critical in deployments where bootstrap credentials like the Login Client PAT or machine keys are stored in locations reachable by the API process, allowing attackers to escalate privileges from an organization-level administrator to an instance-wide administrator.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation collapses multi-tenant isolation, granting an organization administrator unauthorized access to host-level secrets and sensitive credentials. In self-hosted environments that follow documented bootstrap patterns, this leads to full instance control (IAM_OWNER). The vulnerability impacts all ZITADEL deployments utilizing Actions V1 on affected versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade ZITADEL 4.x deployments to version 4.16.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade ZITADEL 3.x deployments to version 3.4.13 or later immediately.\u003c/li\u003e\n\u003cli\u003eIn multi-tenant environments, strictly limit the assignment of \u003ccode\u003eorg.action.write\u003c/code\u003e and \u003ccode\u003eorg.flow.write\u003c/code\u003e permissions to trusted administrators only.\u003c/li\u003e\n\u003cli\u003eAudit existing Action scripts for the presence of \u003ccode\u003erequire()\u003c/code\u003e calls referencing filesystem paths.\u003c/li\u003e\n\u003cli\u003eRemove or relocate bootstrap credentials (e.g., \u003ccode\u003elogin-client.pat\u003c/code\u003e, machine keys) to volumes or locations not accessible by the ZITADEL API process user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:08:05Z","date_published":"2026-09-24T20:08:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-sandbox-escape/","summary":"An insecure configuration of the goja JavaScript runtime in ZITADEL Actions V1 allows authenticated organization owners to perform a sandbox escape and read arbitrary host files via the require() module loader, leading to potential privilege escalation to instance administrator.","title":"ZITADEL Actions V1 Sandbox Escape via File System Access","url":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-85057","version":"https://jsonfeed.org/version/1.1"}