Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105208— ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens

Quick assessment

Affected
zitadel zitadel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ZITADEL 4.x(4.17.3 之前版本)和 3.x(3.4.15 及更早版本)中,身份提供商(IdP)意图令牌(intent tokens)受到未认证且可篡改的加密保护。这使得已认证的用户能够篡改自己的令牌,使其被用于其他用户的外部登录意图。 攻击者若能预测受害者在传输过程中的意图标识符(intent identifier),并成功赢得时间竞态(timing race),即可调用 /v2/idp_intents 或 /v2/sessions 接口,从而窃取受害者的 IdP 令牌或劫持其会话。

CVSS 7.7 · High

Affected Version Matrix 3

VendorProduct Version RangeStatus
zitadel zitadel < 4.17.3 affected
4.17.3 unaffected
≤ 4.19.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
Source: CVE Program / CVE List V5
Vulnerability Description
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
依赖于未经完整性检查的安全相关输入的混淆或加密
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zitadel zitadel 0 ~ 4.17.3 -
zitadel zitadel 0 ~ 4.19.4 -

II. Public POCs for CVE-2026-105208

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105208

请登录查看更多情报信息。

Other References for CVE-2026-105208 (2)

Same Patch Batch · zitadel · 2026-10-04 · 10 CVEs total

CVE-2026-105207 9.8 CRITICAL ZITADEL before 4.17.3 Account Takeover via External IdP Linking
CVE-2026-105209 9.6 CRITICAL ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollmen
CVE-2026-105215 9.1 CRITICAL ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
CVE-2026-105213 8.2 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE-2026-105210 8.2 HIGH ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
CVE-2026-105211 8.1 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
CVE-2026-105212 7.5 HIGH ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
CVE-2026-105206 5.3 MEDIUM ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servic
CVE-2026-105214 2.3 LOW Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

IV. Related Vulnerabilities

V. Comments for CVE-2026-105208

No comments yet


Leave a comment