Impact
The vulnerability lies in ZITADEL’s handling of external identity provider (IdP) accounts. Before version 4.15.3, the system verified that a user’s email was confirmed locally but did not confirm that the external IdP had verified ownership of that same email before auto‑linking. Consequently, an attacker who could create or manipulate an IdP account could link a forged IdP user to a victim’s ZITADEL account, effectively gaining valid credentials. The weakness is a credential‑management flaw (CWE‑287).
Affected Systems
All ZITADEL versions earlier than 4.15.3 are vulnerable. The issue affects the open‑source ZITADEL identity‑management platform when external IdPs are configured with auto‑linking options.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to control or influence an external IdP that is connected to ZITADEL, after which the attacker can associate a malicious IdP account with the victim’s ZITADEL account and gain unauthorized access.
OpenCVE Enrichment