Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-105207

ZITADEL account linking accepts no auth, enables takeover

ZITADEL 3.0.0-3.4.15 and 4.0.0-4.17.2 linked external IdP accounts without verifying a primary factor or caller permission, allowing account takeover. CVSS 9.8.

cat cve-2026-105207.json
Vendor
ZITADEL
Product
ZITADEL (versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2; fixed in 3.4.16 and 4.17.3)
CVSS
9.8
EPSS (exploit probability)
0.3%
Status
patched
Published

ZITADEL’s external identity provider account-linking flow created links between user accounts and external IdPs without verifying a primary factor or the caller’s permission, including on unauthenticated flows. An attacker with network access could link their own external identity to a target account and take it over.

Affected: versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2.

Fixed in: 3.4.16 and 4.17.3.

Source: GHSA-g8gj-gq47-xgf4.