Impact
ZITADEL versions 3.0.0 through 3.4.15 and all 4.0.0 releases up to 4.17.2 allow an attacker to bind an external identity provider link to another user’s account without verifying a primary factor or the caller’s permissions, even during identify‑only login sessions. An unauthenticated attacker who knows the victim’s login name can create a link between the victim’s account and the attacker’s external IdP identity and then authenticate as the victim, resulting in full account takeover and possible privilege escalation.
Affected Systems
Vendors: ZITADEL. Product: ZITADEL. Affected versions: 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. All releases prior to version 4.17.3 are vulnerable.
Risk and Exploitability
CVSS score of 9.3 signifies critical severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the absence of a primary factor or permission check makes the vulnerability exploitable by attackers who can guess or obtain a victim’s login name. The vulnerability is not listed in CISA KEV, so no known active exploits have been documented; however, the attack surface is broad and the impact is severe. The likely attack vector is an unauthenticated request to the User Service V2 AddIDPLink endpoint or an identify‑only Login V2 session, where the attacker supplies the victim’s user identifier and their own IdP credential.
OpenCVE Enrichment