Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105209— ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment

Quick assessment

Affected
zitadel zitadel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ZITADEL 3.x 在 3.4.15 之前版本,以及 4.x 在 4.17.1 之前版本存在一个不正确的授权漏洞:在发放 Passkey 或无密码模式(passwordless)的注册码时,系统仅检查 HTTP 请求头 中指定的组织,而未验证目标用户所属的实际组织。攻击者若在某一组织中拥有用户写入权限,便可获取同一实例中另一组织下用户的注册码,并注册自己的认证器,从而接管该账户。

CVSS 9.6 · Critical

Affected Version Matrix 4

VendorProduct Version RangeStatus
zitadel zitadel < 4.17.1 affected
4.17.1 unaffected
< 3.4.15 affected
3.4.15 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105209

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment
Source: CVE Program / CVE List V5
Vulnerability Description
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zitadel zitadel 0 ~ 4.17.1 -
zitadel zitadel 0 ~ 3.4.15 -

II. Public POCs for CVE-2026-105209

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105209

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105209 (1)

News Coverage for CVE-2026-105209 (1)

Same Patch Batch · zitadel · 2026-10-04 · 10 CVEs total

CVE-2026-105207 9.8 CRITICAL ZITADEL before 4.17.3 Account Takeover via External IdP Linking
CVE-2026-105215 9.1 CRITICAL ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
CVE-2026-105210 8.2 HIGH ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
CVE-2026-105213 8.2 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE-2026-105211 8.1 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
CVE-2026-105208 7.7 HIGH ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
CVE-2026-105212 7.5 HIGH ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
CVE-2026-105206 5.3 MEDIUM ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servic
CVE-2026-105214 2.3 LOW Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

IV. Related Vulnerabilities

V. Comments for CVE-2026-105209

No comments yet


Leave a comment