Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-105215

ZITADEL Login V1 registration endpoint trusts client data

ZITADEL Login V1 UI trusted client-supplied external account data in the 'external account not found' registration endpoint, allowing auth bypass. CVSS 9.1.

cat cve-2026-105215.json
Vendor
ZITADEL
Product
ZITADEL (before 3.4.14 and 4.x before 4.16.2; fixed in 3.4.14 and 4.16.2)
CVSS
9.1
EPSS (exploit probability)
0.3%
Status
patched
Published

The hosted Login V1 UI in ZITADEL contained an authentication bypass in the “external account not found” registration endpoint: the endpoint trusted client-supplied external account data without server-side verification. Rated critical at CVSS 9.1.

Affected: ZITADEL before 3.4.14 and 4.x before 4.16.2.

Fixed in: 3.4.14 and 4.16.2.

Source: GHSA-738m-7888-jfv8.