๐Ÿ” CVE Alert

CVE-2026-105207

CRITICAL 9.8

ZITADEL before 4.17.3 Account Takeover via External IdP Linking

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.

CWE CWE-306
Vendor zitadel
Product zitadel
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new critical vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

zitadel / zitadel
0 < 4.17.3
zitadel / zitadel
0 โ‰ค 4.19.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4 vulncheck.com: https://www.vulncheck.com/advisories/zitadel-before-4.17.3-account-takeover-via-external-idp-linking

Credits

๐Ÿ” lucasdodgson ๐Ÿ” AdamKorcz grvijayan livio-a