CVE-2026-105207
Deferred Deferred - Pending Action

Unauthenticated Account Linking in ZITADEL

Vulnerability report for CVE-2026-105207, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zitadel zitadel From 3.0.0 (inc) to 3.4.15 (inc)
zitadel zitadel From 4.0.0 (inc) to 4.17.3 (exc)
zitadel zitadel From 4.0.0 (inc) to 4.17.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105207 is a critical vulnerability in ZITADEL versions before 4.17.3 and up to 4.19.4. It allows an unauthenticated attacker who knows a victim's login name to bind their own external identity provider (IdP) identity to the victim's account without verifying primary authentication or permission. This enables the attacker to sign in as the victim.

Detection Guidance

Check ZITADEL logs for suspicious AddIDPLink endpoint requests or external IdP binding attempts. Monitor for multiple failed login attempts followed by successful logins from unexpected IdPs. Review user account changes for unauthorized external IdP associations.

Impact Analysis

An attacker could gain full access to a victim's account, including sensitive data and actions, without needing the victim's password or MFA factors. This could lead to data breaches, unauthorized transactions, or impersonation of the victim.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using affected ZITADEL versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Upgrade ZITADEL to version 4.17.3 or later immediately. If using version 3.x, upgrade to a patched 4.x version as 3.x is end-of-life and unsupported. Disable Account Manual Linking if enabled.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105207. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart