Improper Authorization Risk in ZITADEL Product by ZITADEL
CVE-2026-105209

9.3CRITICAL

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105209?

ZITADEL versions 3.x prior to 3.4.15 and 4.x prior to 4.17.1 are exposed to an improper authorization vulnerability that enables attackers to exploit passkey or passwordless enrollment processes. The flaw arises from the system's failure to verify the organization affiliation of the target user when issuing enrollment codes. This allows attackers with user-write permissions in one organization to acquire codes intended for users in another organization, enabling them to register their own authenticators and gain unauthorized access to accounts across the same instance.

Affected Version(s)

zitadel 0 < 4.17.1

zitadel 0 < 3.4.15

zitadel 4.17.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rud
rz1027
lyhtheori
AdamKorcz
IAM-marco
grvijayan
.