CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-105207 — ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user ...

·Source: NIST NVD

Updated:

Executive Summary

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account

Analysis

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim. CVSS Score: 9.8. Published: 2026-10-04T15:16:31.677.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105207
Source Attribution

Originally published by NIST NVD on Oct 4, 2026. Verified by: NIST.

Related Threats