No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session. | |
| Title | ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-649 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:02.664Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105208
No data.
Status : Deferred
Published: 2026-10-04T15:16:31.843
Modified: 2026-10-04T15:16:31.963
Link: CVE-2026-105208
No data.
OpenCVE Enrichment
Updated: 2026-10-04T15:30:15Z
-
CWE-649
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking