PT-2026-104631 · Zitadel · Zitadel
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 3.0.0 through 3.4.15
ZITADEL versions 4.0.0 through 4.17.2
Description
An issue exists where links are created between user accounts and external identity providers without verifying a primary factor or the caller's permission. This occurs during identify-only Login V2 sessions and via the User Service V2 'AddIDPLink' endpoint. An unauthenticated attacker who knows a victim's login name can bind their own external identity provider identity to the victim's account to hijack it and sign in as the victim.
Recommendations
Update ZITADEL versions 3.0.0 through 3.4.15 to a version where this issue is resolved.
Update ZITADEL versions 4.0.0 through 4.17.2 to version 4.17.3 or later.
Restrict access to the 'AddIDPLink' endpoint in User Service V2 to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel