CVE-2026-105208
Deferred Deferred - Pending Action

IdP Intent Token Tampering in ZITADEL

Vulnerability report for CVE-2026-105208, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 3.4.15 (inc)
zitadel zitadel to 4.17.3 (exc)
zitadel zitadel From 3.0.0 (inc) to 3.4.15 (inc)
zitadel zitadel From 4.17.3 (inc)
zitadel zitadel to 4.19.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-649 The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 involves IdP intent tokens being protected with unauthenticated, malleable encryption. Attackers can tamper with their own tokens to impersonate another user's external login intent. By predicting a victim's intent identifier and winning a timing race, they can steal IdP tokens or hijack sessions via endpoints like /v2/idp_intents or /v2/sessions.

Detection Guidance

Detecting this vulnerability requires checking ZITADEL versions and monitoring for suspicious activity. Verify installed versions with commands like 'zitadel version' or check package managers. Inspect logs for repeated failed login attempts or unusual session creation patterns, especially around /v2/idp_intents or /v2/sessions endpoints. Look for timing anomalies in intent token generation or redemption.

Impact Analysis

An attacker could steal your IdP tokens (including access and refresh tokens) or hijack your session if you are using an external IdP. This requires predicting your intent identifier within a 10-millisecond window and winning a timing race. The attack has a low success probability but could lead to unauthorized access to your account or data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations using vulnerable ZITADEL versions may face compliance breaches if user data is exposed or accessed without authorization.

Mitigation Strategies

Upgrade ZITADEL to version 4.17.3 or later immediately. If using 3.x, upgrade to 4.x as 3.x is end-of-life. Enforce strict rate limiting and bot protection. Disable external IdP usage temporarily if possible. Monitor for active exploitation attempts and revoke suspicious sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105208. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart