Incorrect Authorization Vulnerability in ZITADEL User Service API
CVE-2026-105206

5.3MEDIUM

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105206?

The User Service API in ZITADEL versions 3.0.0 through 3.4.15 and 4.x prior to 4.17.3 suffers from an incorrect authorization issue. This vulnerability allows authenticated users with org-scoped user.read permissions to access sensitive information regarding authentication methods registered by users in other organizations. Specifically, these users can exploit the GET /v2/users/{userId}/authentication_methods endpoint to enumerate authentication method types utilized by users not belonging to their own organization. This flaw raises significant concerns about user data exposure across organizational boundaries.

Affected Version(s)

zitadel 0 < 4.17.3

zitadel 0 <= 4.19.4

zitadel 4.17.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

IAM-marco
livio-a
isazajuancarlos
dmitrymaranik
.