Cyber & AI intelligence
Wasteland.
Briefs indexed3010
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-105215 2026-10-04

ZITADEL Login V1 Flaw Lets Attackers Pre-Hijack Accounts via Forged External IdP Data (CVE-2026-105215)

"CVE-2026-105215 is a critical authentication bypass in ZITADEL's hosted Login V1 UI. Unauthenticated attackers can create an account in advance that is bound to a victim's external identity provider (IdP) identity, and…"

CVE-2026-105215 is a critical authentication bypass in ZITADEL's hosted Login V1 UI. Unauthenticated attackers can create an account in advance that is bound to a victim's external identity provider (IdP) identity, and the victim is then signed into that account when they later log in.

What Is It

ZITADEL versions before 3.4.14, and 4.x versions before 4.16.2, contain an authentication bypass in the hosted Login V1 UI. The flaw is in the "external account not found" registration endpoint. That endpoint trusts external identity fields sent by the client even when no IdP callback has been completed.

An unauthenticated attacker can send forged IDPConfigID and ExternalUserID values to this endpoint. This creates an account bound to the victim's external IdP identity in advance. When the victim later completes a genuine external login, they are signed into the account the attacker created.

The weakness is classified as CWE-290 (Authentication Bypass by Spoofing).

Why It Matters

VulnCheck scores this flaw 9.1 (CRITICAL) under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) and 9.3 (CRITICAL) under CVSS 4.0. According to the vector, the attack:

Confidentiality and integrity impacts are both rated High. Availability impact is rated None.

ZITADEL is an identity platform, so a flaw that binds attacker-controlled accounts to real users' federated identities weakens the trust that downstream authentication depends on.

As of this writing, CVE-2026-105215 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The supplied data does not confirm active exploitation. NVD lists the record's status as "Deferred."

What's Vulnerable

Affected product: ZITADEL (vendor: zitadel)

The flaw affects the hosted Login V1 UI, specifically the "external account not found" registration flow used with external IdPs.

Patch Status

Fixed versions are listed in the advisory data:

Organizations running ZITADEL with external IdP login on the hosted Login V1 UI should upgrade to a fixed release. See the vendor's GitHub security advisory for full remediation guidance. CISA has not issued a required action because the CVE is not listed in the KEV catalog.

Sources