Account Linking Vulnerability in ZITADEL by ZITADEL
CVE-2026-105207

9.3CRITICAL

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105207?

ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 prior to 4.17.3 contain a serious security flaw that allows an unauthenticated attacker to link their own external identity provider (IdP) to a victim's account without proper permission checks. This vulnerability occurs during identity-only Login V2 sessions and through the User Service V2 AddIDPLink endpoint, enabling an attacker who knows the victim's login name to take over the victim's account. Proper verification mechanisms are not in place, exposing users to significant risks.

Affected Version(s)

zitadel 0 < 4.17.3

zitadel 0 <= 4.19.4

zitadel 4.17.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lucasdodgson
AdamKorcz
grvijayan
livio-a
.