CVE-2026-105206: ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service
ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authenticationmethods to learn which authentication method types users in other organizations have registered.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated as a member of an organization and hold that organization's org-scoped user.read permission. Unauthenticated users are not described as able to exploit it.
What information can be exposed?
The affected endpoint can reveal which authentication method types a target user in another organization has registered. The provided information does not indicate that the methods themselves, credentials, or other user data are exposed.
How can I determine whether my deployment is affected?
Deployments running ZITADEL 3.0.0 through 3.4.15, or a 4.x release earlier than 4.17.3, are affected. Review whether users with org-scoped user.read can access GET /v2/users/{userId}/authentication_methods for user IDs belonging to other organizations.