๐Ÿ” CVE Alert

CVE-2026-105206

UNKNOWN 0.0

ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.

CWE CWE-863
Vendor zitadel
Product zitadel
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new unknown vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

zitadel / zitadel
0 < 4.17.3
zitadel / zitadel
0 โ‰ค 4.19.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-j344-gqv4-84ff vulncheck.com: https://www.vulncheck.com/advisories/zitadel-before-4.17.3-cross-organization-authentication-method-enumeration-via-user-service

Credits

IAM-marco livio-a ๐Ÿ” isazajuancarlos ๐Ÿ” dmitrymaranik