Cyber & AI intelligence
Wasteland.
Briefs indexed3010
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-105207 2026-10-04

ZITADEL Flaw Lets Unauthenticated Attackers Take Over Accounts via External IdP Linking (CVE-2026-105207)

"CVE-2026-105207 is a critical missing-authentication flaw in ZITADEL that lets an unauthenticated attacker who knows a victim's login name link their own external identity provider to the victim's account and then sign…"

CVE-2026-105207 is a critical missing-authentication flaw in ZITADEL that lets an unauthenticated attacker who knows a victim's login name link their own external identity provider to the victim's account and then sign in as the victim.

What Is It

ZITADEL links user accounts to external identity providers (IdPs) without first checking a primary factor or whether the caller has permission to do so. According to the NVD description, this happens on identify-only Login V2 sessions and through the User Service V2 AddIDPLink endpoint.

The flaw is classified as CWE-306 (Missing Authentication for Critical Function). VulnCheck reported it, and the record was published on October 4, 2026. NVD lists its status as "Deferred."

Why It Matters

The NVD description says an attacker who knows the victim's login name can bind an external IdP identity they control to the victim's account and authenticate as that user. The result is full account takeover. The supplied data doesn't say whether other conditions must also be met, such as which external IdPs the instance has configured or allows. Defenders shouldn't assume that knowing a login name is always enough on its own.

Severity scores:

ZITADEL is an identity platform, so a compromised account there may expose any application that relies on it for authentication.

Exploitation status: No CISA KEV entry was supplied for this CVE. The supplied data doesn't confirm active exploitation, and there is no KEV-mandated required action or due date.

What's Vulnerable

The NVD description lists these affected versions:

The structured affected-version data doesn't fully agree with this. One entry marks versions below 4.17.3 as affected and 4.17.3 as unaffected. A second entry marks all versions up to and including 4.19.4 as affected. Defenders should check the vendor advisory to confirm which builds are actually fixed.

The NVD record lists no CPEs.

Patch Status

On the 4.x branch, the NVD description and one affected-version entry point to 4.17.3 as the fixed release. The second entry, which lists versions through 4.19.4 as affected, leaves this uncertain. The supplied data doesn't name a fixed release for the 3.x branch.

Organizations running ZITADEL should:

  1. Review the GitHub security advisory (GHSA-g8gj-gq47-xgf4) for authoritative fixed versions.
  2. Upgrade to a release the vendor confirms as patched.
  3. Treat this as a priority because the flaw is unauthenticated and leads to account takeover.

Sources