CVE-2026-105209
Deferred
Deferred - Pending Action
Improper Authorization in ZITADEL Leading to Account Takeover
Vulnerability report for CVE-2026-105209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-04
Last updated on: 2026-10-04
Assigner: VulnCheck
Description
Description
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zitadel | zitadel | to 3.4.15 (exc) |
| zitadel | zitadel | to 4.17.1 (exc) |
| zitadel | zitadel | to 3.4.15|end_excluding=4.17.1 (exc) |
| zitadel | zitadel | From 3.0.0 (inc) to 3.4.14 (inc) |
| zitadel | zitadel | From 4.0.0 (inc) to 4.17.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |