ZITADEL Patches Four Auth Bypass Flaws, Two Critical
ZITADEL patched four authentication bypass CVEs this week, including CVE-2026-105207 at CVSS 9.8 and CVE-2026-105215 at CVSS 9.1. None confirmed exploited in the wild.

Four authentication bypass vulnerabilities patched in ZITADEL this week. Two are rated critical.
Highest severity: CVE-2026-105207, CVSS 9.8. ZITADEL’s external identity provider account-linking flow created links between user accounts and external IdPs without verifying a primary factor or caller permission, including on unauthenticated paths. An attacker with network access could link their own external IdP identity to a target account and take it over. Affected: versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. Fixed in 3.4.16 and 4.17.3. Source: GHSA-g8gj-gq47-xgf4.
Second critical: CVE-2026-105215, CVSS 9.1. ZITADEL’s hosted Login V1 UI trusted client-supplied external account data in the “external account not found” registration endpoint. No server-side verification of the supplied data. Affected: before 3.4.14 and 4.x before 4.16.2. Source: GHSA-738m-7888-jfv8.
Two additional high-severity flaws in the same patch window:
CVE-2026-105211, CVSS 8.1. Login V2 exposed OTP codes via the returnCode delivery type. An unauthenticated attacker could retrieve codes and take over an account without needing the user’s credentials. Fixed in 4.17.1. Source: GHSA-3gwm-5wx8-4gm6.
CVE-2026-105212, CVSS 7.5. Both Login V1 and V2 accepted passkey and authenticator enrollment on identify-only login flows, before the user’s identity was confirmed. Affected: 3.x before 3.4.14, 4.x before 4.16.2. Source: GHSA-45f2-5q3r-xgg6.
Exploitation status: Not confirmed in the wild as of October 5, 2026. None appear on CISA’s Known Exploited Vulnerabilities catalog.
What to do. Check your ZITADEL version against the matrix below. Patch to the fixed release for your branch.
| CVE | Severity | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2026-105207 | Critical | 9.8 | 3.0.0-3.4.15, 4.0.0-4.17.2 | 3.4.16, 4.17.3 |
| CVE-2026-105215 | Critical | 9.1 | before 3.4.14, 4.x before 4.16.2 | 3.4.14, 4.16.2 |
| CVE-2026-105211 | High | 8.1 | 4.x before 4.17.1 | 4.17.1 |
| CVE-2026-105212 | High | 7.5 | 3.x before 3.4.14, 4.x before 4.16.2 | 3.4.14, 4.16.2 |
Full advisory list: github.com/zitadel/zitadel/security/advisories.
Auth bypass flaws in identity platforms have been a recurring pattern this week. See also: Fleet MDM Auth Bypass Allows Rogue Device Enrollment, YesWiki Flaws Let Attackers Spoof Identity, Hijack SMTP, and Microsoft Fabric Auth Bypass Reaches CVSS 10.0. More on the threat intelligence beat.
- [ CRITICAL ]CVE-2026-105207ZITADEL account linking accepts no auth, enables takeover
- [ CRITICAL ]CVE-2026-105215ZITADEL Login V1 registration endpoint trusts client data
- [ HIGH ]CVE-2026-105211ZITADEL Login V2 OTP codes exposed via returnCode type
- [ HIGH ]CVE-2026-105212ZITADEL Login V1/V2 accepted passkey enrollment before auth
Found this useful? Share it.


