PT-2026-104631 · Zitadel · Zitadel

·

CVE-2026-105207

·

Published

2026-10-04

·

Updated

2026-10-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZITADEL versions 3.0.0 through 3.4.15 ZITADEL versions 4.0.0 through 4.17.2
Description An issue exists where links are created between user accounts and external identity providers without verifying a primary factor or the caller's permission. This occurs during identify-only Login V2 sessions and via the User Service V2 'AddIDPLink' endpoint. An unauthenticated attacker who knows a victim's login name can bind their own external identity provider identity to the victim's account to hijack it and sign in as the victim.
Recommendations Update ZITADEL versions 3.0.0 through 3.4.15 to a version where this issue is resolved. Update ZITADEL versions 4.0.0 through 4.17.2 to version 4.17.3 or later. Restrict access to the 'AddIDPLink' endpoint in User Service V2 to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105207
GHSA-G8GJ-GQ47-XGF4

Affected Products

Zitadel