Description
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Published: 2026-10-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Account Takeover
Action: Immediate Patch
AI Analysis

Impact

ZITADEL versions 3.0.0 through 3.4.15 and all 4.0.0 releases up to 4.17.2 allow an attacker to bind an external identity provider link to another user’s account without verifying a primary factor or the caller’s permissions, even during identify‑only login sessions. An unauthenticated attacker who knows the victim’s login name can create a link between the victim’s account and the attacker’s external IdP identity and then authenticate as the victim, resulting in full account takeover and possible privilege escalation.

Affected Systems

Vendors: ZITADEL. Product: ZITADEL. Affected versions: 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. All releases prior to version 4.17.3 are vulnerable.

Risk and Exploitability

CVSS score of 9.3 signifies critical severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the absence of a primary factor or permission check makes the vulnerability exploitable by attackers who can guess or obtain a victim’s login name. The vulnerability is not listed in CISA KEV, so no known active exploits have been documented; however, the attack surface is broad and the impact is severe. The likely attack vector is an unauthenticated request to the User Service V2 AddIDPLink endpoint or an identify‑only Login V2 session, where the attacker supplies the victim’s user identifier and their own IdP credential.

Generated by OpenCVE AI on October 4, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to version 4.17.3 or later, which removes the insecure IDP linking behavior.
  • If an upgrade cannot be performed immediately, configure the system to restrict external IdP linking to only authenticated users and enforce role‑based permission checks.
  • Audit existing IdP link associations regularly and delete any that were created by unauthorized users or are no longer needed.
  • Enable multi‑factor authentication for all user accounts to reduce the risk of credential compromise.

Generated by OpenCVE AI on October 4, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Title ZITADEL before 4.17.3 Account Takeover via External IdP Linking
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-306
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:02.024Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:31.677

Modified: 2026-10-04T15:16:31.793

Link: CVE-2026-105207

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T17:30:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function