Description
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3.
Published: 2026-07-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in ZITADEL’s handling of external identity provider (IdP) accounts. Before version 4.15.3, the system verified that a user’s email was confirmed locally but did not confirm that the external IdP had verified ownership of that same email before auto‑linking. Consequently, an attacker who could create or manipulate an IdP account could link a forged IdP user to a victim’s ZITADEL account, effectively gaining valid credentials. The weakness is a credential‑management flaw (CWE‑287).

Affected Systems

All ZITADEL versions earlier than 4.15.3 are vulnerable. The issue affects the open‑source ZITADEL identity‑management platform when external IdPs are configured with auto‑linking options.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to control or influence an external IdP that is connected to ZITADEL, after which the attacker can associate a malicious IdP account with the victim’s ZITADEL account and gain unauthorized access.

Generated by OpenCVE AI on July 29, 2026 at 10:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to version 4.15.3 or newer, which enforces IdP email verification before auto‑linking.
  • Configure all external IdPs to require verified ownership of the email address and disable automatic linking for unverified addresses.
  • Audit existing user accounts for bindings to external IdPs and revoke any that appear to be incorrectly linked before remediation.

Generated by OpenCVE AI on July 29, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Zitadel
Zitadel zitadel
Vendors & Products Zitadel
Zitadel zitadel

Fri, 10 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3.
Title ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-13T18:09:47.186Z

Reserved: 2026-06-22T16:39:01.043Z

Link: CVE-2026-56666

cve-icon Vulnrichment

Updated: 2026-07-13T18:09:43.700Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses