CVE Record
[ CRITICAL ]CVE-2026-105207
ZITADEL account linking accepts no auth, enables takeover
ZITADEL 3.0.0-3.4.15 and 4.0.0-4.17.2 linked external IdP accounts without verifying a primary factor or caller permission, allowing account takeover. CVSS 9.8.
- Vendor
- ZITADEL
- Product
- ZITADEL (versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2; fixed in 3.4.16 and 4.17.3)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
ZITADEL’s external identity provider account-linking flow created links between user accounts and external IdPs without verifying a primary factor or the caller’s permission, including on unauthenticated flows. An attacker with network access could link their own external identity to a target account and take it over.
Affected: versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2.
Fixed in: 3.4.16 and 4.17.3.
Source: GHSA-g8gj-gq47-xgf4.
