Account Linking Vulnerability in ZITADEL by ZITADEL
CVE-2026-105207
9.3CRITICAL
What is CVE-2026-105207?
ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 prior to 4.17.3 contain a serious security flaw that allows an unauthenticated attacker to link their own external identity provider (IdP) to a victim's account without proper permission checks. This vulnerability occurs during identity-only Login V2 sessions and through the User Service V2 AddIDPLink endpoint, enabling an attacker who knows the victim's login name to take over the victim's account. Proper verification mechanisms are not in place, exposing users to significant risks.
Affected Version(s)
zitadel 0 < 4.17.3
zitadel 0 <= 4.19.4
zitadel 4.17.3
