Improper Authorization Risk in ZITADEL Product by ZITADEL
CVE-2026-105209
9.3CRITICAL
What is CVE-2026-105209?
ZITADEL versions 3.x prior to 3.4.15 and 4.x prior to 4.17.1 are exposed to an improper authorization vulnerability that enables attackers to exploit passkey or passwordless enrollment processes. The flaw arises from the system's failure to verify the organization affiliation of the target user when issuing enrollment codes. This allows attackers with user-write permissions in one organization to acquire codes intended for users in another organization, enabling them to register their own authenticators and gain unauthorized access to accounts across the same instance.
Affected Version(s)
zitadel 0 < 4.17.1
zitadel 0 < 3.4.15
zitadel 4.17.1
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
rud
rz1027
lyhtheori
AdamKorcz
IAM-marco
grvijayan
