Description
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Published: 2026-10-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass leading to account hijacking
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an authentication bypass in the hosted Login V1 UI of ZITADEL. The external account creation endpoint trusts client supplied external identity fields even when an IdP callback has not yet been completed. As a result, unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to create an account that is bound to a victim’s external IdP identity. When the legitimate user later logs in via that external IdP, the forged account is used, allowing the attacker to assume the victim’s account. The weakness is classified as CWE‑290, Authentication Bypass.

Affected Systems

Affected systems are ZITADEL servers running any version prior to 3.4.14 or any 4.x release earlier than 4.16.2. The vulnerability is present in the zitadel:zitadel product as listed in the CNA vendor/product names.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating a critical severity. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of known exploitation does not mitigate the high intrinsic risk. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this issue remotely by sending crafted HTTP requests to the external account creation endpoint, as the bug is fully triggered without any prior authentication. The likely attack vector is a remote web-based request that does not require login, making the vulnerability usable from anywhere with network access to the Login UI.

Generated by OpenCVE AI on October 4, 2026 at 15:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update ZITADEL to version 4.16.2 or later (or 3.4.14+).
  • Configure ZITADEL to enforce a completed IdP callback before allowing account creation tied to an external identity.
  • Enable monitoring of external account creation requests and set alerts for unexpected ExternalUserID values.

Generated by OpenCVE AI on October 4, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Title ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-290
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:07.389Z

Reserved: 2026-10-04T13:04:00.478Z

Link: CVE-2026-105215

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:32.993

Modified: 2026-10-04T15:16:33.107

Link: CVE-2026-105215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T15:45:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing