Incorrect Authorization Vulnerability in ZITADEL User Service API
CVE-2026-105206
5.3MEDIUM
What is CVE-2026-105206?
The User Service API in ZITADEL versions 3.0.0 through 3.4.15 and 4.x prior to 4.17.3 suffers from an incorrect authorization issue. This vulnerability allows authenticated users with org-scoped user.read permissions to access sensitive information regarding authentication methods registered by users in other organizations. Specifically, these users can exploit the GET /v2/users/{userId}/authentication_methods endpoint to enumerate authentication method types utilized by users not belonging to their own organization. This flaw raises significant concerns about user data exposure across organizational boundaries.
Affected Version(s)
zitadel 0 < 4.17.3
zitadel 0 <= 4.19.4
zitadel 4.17.3
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
IAM-marco
livio-a
isazajuancarlos
dmitrymaranik
