CVE-2026-105207
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zitadel | zitadel | 0 < 4.17.3 | affected |
| zitadel | zitadel | 4.17.3 | unaffected |
| zitadel | zitadel | 0 <= 4.19.4 | affected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-g8gj-gq47-xgf4
- https://www.vulncheck.com/advisories/zitadel-before-4.17.3-account-takeover-via-external-idp-linking
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.