PT-2026-104639 · Zitadel · Zitadel
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions prior to 3.4.14
ZITADEL versions 4.x prior to 4.16.2
Description
An authentication bypass exists in the hosted Login V1 UI. The issue occurs because the registration endpoint for external accounts not found trusts external identity fields provided by the client without requiring a completed Identity Provider (IdP) callback. An unauthenticated attacker can submit forged
IDPConfigID and ExternalUserID values to pre-create an account linked to a victim's external IdP identity. When the victim subsequently performs a legitimate external login, they are signed into the pre-created account.Recommendations
Update ZITADEL to version 3.4.14 or later.
Update ZITADEL to version 4.16.2 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel