Impact
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization flaw: when issuing passkey or passwordless enrollment codes it only checks the organization ID in the x-zitadel-orgid header, ignoring the target user’s organization. An attacker wielding user‑write permission in one organization can therefore obtain an enrollment code for a user in a different organization on the same instance and register an authenticator, effectively taking over that account.
Affected Systems
The vulnerability affects the ZITADEL identity platform in releases 3.x before 3.4.15 and 4.x before 4.17.1. These versions are identified by the vendor and product name ZITADEL.
Risk and Exploitability
The CVSS base score of 9.3 indicates critical severity. EPSS information is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attacker is an internal user possessing user‑write privileges within one organization; such an actor can exploit the header bypass to generate passkey enrollment codes for accounts in other organizations and then register an authenticator to seize those accounts.
OpenCVE Enrichment