Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim. | |
| Title | ZITADEL before 4.17.3 Account Takeover via External IdP Linking | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:02.024Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105207
No data.
Status : Deferred
Published: 2026-10-04T15:16:31.677
Modified: 2026-10-04T15:16:31.793
Link: CVE-2026-105207
No data.
OpenCVE Enrichment
Updated: 2026-10-04T17:30:16Z