CVE-2026-105206
ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
| CWE | CWE-863 |
| Vendor | zitadel |
| Product | zitadel |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for zitadel zitadel
Be the first to know when new unknown vulnerabilities affecting zitadel zitadel are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
zitadel / zitadel
0 < 4.17.3
zitadel / zitadel
0 โค 4.19.4
References
Credits
IAM-marco livio-a ๐ isazajuancarlos ๐ dmitrymaranik