CVE-2026-105208
Deferred
Deferred - Pending Action
IdP Intent Token Tampering in ZITADEL
Vulnerability report for CVE-2026-105208, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-04
Last updated on: 2026-10-04
Assigner: VulnCheck
Description
Description
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zitadel | zitadel | to 3.4.15 (inc) |
| zitadel | zitadel | to 4.17.3 (exc) |
| zitadel | zitadel | From 3.0.0 (inc) to 3.4.15 (inc) |
| zitadel | zitadel | From 4.17.3 (inc) |
| zitadel | zitadel | to 4.19.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-649 | The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified. |