CVE Record
[ CRITICAL ]CVE-2026-105215
ZITADEL Login V1 registration endpoint trusts client data
ZITADEL Login V1 UI trusted client-supplied external account data in the 'external account not found' registration endpoint, allowing auth bypass. CVSS 9.1.
- Vendor
- ZITADEL
- Product
- ZITADEL (before 3.4.14 and 4.x before 4.16.2; fixed in 3.4.14 and 4.16.2)
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
The hosted Login V1 UI in ZITADEL contained an authentication bypass in the “external account not found” registration endpoint: the endpoint trusted client-supplied external account data without server-side verification. Rated critical at CVSS 9.1.
Affected: ZITADEL before 3.4.14 and 4.x before 4.16.2.
Fixed in: 3.4.14 and 4.16.2.
Source: GHSA-738m-7888-jfv8.
