Critical severity9.8NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026
CVE-2026-105207
CVE-2026-105207
Description
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.