Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105207— ZITADEL before 4.17.3 Account Takeover via External IdP Linking

Quick assessment

Affected
zitadel zitadel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ZITADEL 3.0.0 至 3.4.15 版本以及 4.0.0 至 4.17.3 之前版本在用户账号与外部身份提供商(External Identity Providers)之间建立关联时,未验证主认证因子(primary factor)或调用者的权限,即使在仅标识的登录 V2(identify-only Login V2)会话中,以及通过用户服务 V2 的 AddIDPLink 端点也是如此。未认证的攻击者若知晓受害者的登录名,便可将自身的外部身份提供商身份绑定到受害者账号上,随后即可冒充该受害者登录系统。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1199 · Trusted Relationship

Affected Version Matrix 3

VendorProduct Version RangeStatus
zitadel zitadel < 4.17.3 affected
4.17.3 unaffected
≤ 4.19.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105207

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ZITADEL before 4.17.3 Account Takeover via External IdP Linking
Source: CVE Program / CVE List V5
Vulnerability Description
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zitadel zitadel 0 ~ 4.17.3 -
zitadel zitadel 0 ~ 4.19.4 -

II. Public POCs for CVE-2026-105207

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105207

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105207 (2)

Same Patch Batch · zitadel · 2026-10-04 · 10 CVEs total

CVE-2026-105209 9.6 CRITICAL ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollmen
CVE-2026-105215 9.1 CRITICAL ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
CVE-2026-105210 8.2 HIGH ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
CVE-2026-105213 8.2 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE-2026-105211 8.1 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
CVE-2026-105208 7.7 HIGH ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
CVE-2026-105212 7.5 HIGH ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
CVE-2026-105206 5.3 MEDIUM ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servic
CVE-2026-105214 2.3 LOW Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

IV. Related Vulnerabilities

V. Comments for CVE-2026-105207

No comments yet


Leave a comment