Cyber & AI intelligence
Wasteland.
Briefs indexed3010
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-105209 2026-10-04

ZITADEL Cross-Organization Account Takeover via Passkey Enrollment (CVE-2026-105209)

"A critical missing-authorization flaw in ZITADEL lets a user with user-write permission in one organization obtain passkey or passwordless enrollment codes for users in other organizations on the same instance, and use…"

A critical missing-authorization flaw in ZITADEL lets a user with user-write permission in one organization obtain passkey or passwordless enrollment codes for users in other organizations on the same instance, and use them to take over those accounts.

What Is It

CVE-2026-105209 is an improper authorization vulnerability (CWE-862, Missing Authorization) in the ZITADEL identity platform. When ZITADEL issues passkey or passwordless enrollment codes, it checks only the organization named in the x-zitadel-orgid header. It does not check which organization the target user belongs to.

An attacker who holds user-write permission in any one organization can therefore request an enrollment code for a user in a different organization on the same ZITADEL instance. The attacker can then register their own authenticator to that user and take over the account.

VulnCheck disclosed the vulnerability, and NVD published it on 2026-10-04. NVD currently lists the record as "Deferred."

Why It Matters

The attack works over the network, has low complexity, needs only low privileges and requires no user interaction. The scope is rated "Changed," which reflects how far the damage reaches: an organization boundary is meant to separate tenants, and this flaw lets an attacker cross it. ZITADEL is an identity provider, so a taken-over account could give the attacker access to whatever applications rely on that identity. Both confidentiality and integrity impacts are rated High.

Multi-tenant deployments are the most exposed. These are instances where several organizations share one ZITADEL instance and where accounts with user-write permissions exist in more than one organization.

The supplied CISA KEV data contains no entry for this CVE, so active exploitation in the wild is not confirmed at this time.

What's Vulnerable

The issue affects the passkey and passwordless enrollment code issuance flow on instances that host multiple organizations.

Patch Status

Fixed versions are available:

No CISA KEV remediation deadline applies, because the CVE is not listed in KEV. Given the critical rating and the account-takeover impact, administrators of multi-organization ZITADEL instances should treat this upgrade as a priority. They should also review the vendor advisory for further guidance.

Sources