CVE-2026-105215
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL via Forged External Identity

Vulnerability report for CVE-2026-105215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 3.4.14 (exc)
zitadel zitadel to 4.16.2 (exc)
zitadel zitadel From 3.0.0 (inc) to 3.4.13 (inc)
zitadel zitadel From 4.0.0 (inc) to 4.16.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in ZITADEL's Login V1 UI that allows unauthenticated attackers to pre-create user accounts linked to victims' external identity provider (IdP) identities. By submitting forged IDPConfigID and ExternalUserID values to the registration endpoint without completing an IdP callback, attackers can bind accounts to victims' public external user IDs. When victims later log in using their genuine IdP credentials, they unknowingly access the attacker's pre-created account, effectively hijacking the victim's account.

Detection Guidance

To detect this vulnerability, check if your ZITADEL instance is running a vulnerable version (before 4.16.2 or 3.4.14) by running version checks. Inspect logs for unusual account creation events, especially those linked to external IdP identities without completed callbacks. Look for pre-created accounts with forged IDPConfigID or ExternalUserID values.

Impact Analysis

If you use ZITADEL versions before 4.16.2 or 3.4.14 with external IdPs that allow manual account creation, attackers could hijack your account by pre-binding it to their control. This could lead to unauthorized access to your data, impersonation, or further attacks using your identity. The impact is severe as it requires no privileges or user interaction for exploitation.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control, such as GDPR's integrity and confidentiality principles or HIPAA's access controls. Unauthorized account hijacking could lead to unauthorized data access, breaching regulatory obligations for protecting sensitive information. Organizations using vulnerable versions may face compliance violations and associated penalties.

Mitigation Strategies

Immediately upgrade ZITADEL to versions 4.16.2 or 3.4.14 or later. If upgrading is not possible, disable manual account creation on all configured external IdPs as a temporary workaround. Review and remove any suspicious pre-created accounts linked to external IdP identities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart