PT-2026-104632 · Zitadel · Zitadel

·

CVE-2026-105208

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

8.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.x through 4.17.2 ZITADEL versions 3.x through 3.4.15
Description Authenticated users can tamper with their own IdP intent tokens due to the use of unauthenticated, malleable encryption. This allows a user to modify a token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can use the '/v2/idp intents' or '/v2/sessions' endpoints to steal IdP tokens or hijack a session.
Recommendations Update ZITADEL versions 4.x to 4.17.3 or later. Update ZITADEL versions 3.x to 3.4.16 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105208
GHSA-JH3M-CR2X-QP88

Affected Products

Zitadel