Impact
The vulnerability is an authentication bypass in the hosted Login V1 UI of ZITADEL. The external account creation endpoint trusts client supplied external identity fields even when an IdP callback has not yet been completed. As a result, unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to create an account that is bound to a victim’s external IdP identity. When the legitimate user later logs in via that external IdP, the forged account is used, allowing the attacker to assume the victim’s account. The weakness is classified as CWE‑290, Authentication Bypass.
Affected Systems
Affected systems are ZITADEL servers running any version prior to 3.4.14 or any 4.x release earlier than 4.16.2. The vulnerability is present in the zitadel:zitadel product as listed in the CNA vendor/product names.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating a critical severity. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of known exploitation does not mitigate the high intrinsic risk. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this issue remotely by sending crafted HTTP requests to the external account creation endpoint, as the bug is fully triggered without any prior authentication. The likely attack vector is a remote web-based request that does not require login, making the vulnerability usable from anywhere with network access to the Login UI.
OpenCVE Enrichment