Critical severity9.6NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026
CVE-2026-105209
CVE-2026-105209
Description
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.