PT-2026-104632 · Zitadel · Zitadel
CVSS v4.0
8.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.x through 4.17.2
ZITADEL versions 3.x through 3.4.15
Description
Authenticated users can tamper with their own IdP intent tokens due to the use of unauthenticated, malleable encryption. This allows a user to modify a token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can use the '/v2/idp intents' or '/v2/sessions' endpoints to steal IdP tokens or hijack a session.
Recommendations
Update ZITADEL versions 4.x to 4.17.3 or later.
Update ZITADEL versions 3.x to 3.4.16 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel