PT-2026-104639 · Zitadel · Zitadel

·

CVE-2026-105215

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions prior to 3.4.14 ZITADEL versions 4.x prior to 4.16.2
Description An authentication bypass exists in the hosted Login V1 UI. The issue occurs because the registration endpoint for external accounts not found trusts external identity fields provided by the client without requiring a completed Identity Provider (IdP) callback. An unauthenticated attacker can submit forged IDPConfigID and ExternalUserID values to pre-create an account linked to a victim's external IdP identity. When the victim subsequently performs a legitimate external login, they are signed into the pre-created account.
Recommendations Update ZITADEL to version 3.4.14 or later. Update ZITADEL to version 4.16.2 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105215

Affected Products

Zitadel