CVE-2026-105207: ZITADEL before 4.17.3 Account Takeover via External IdP Linking
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 are affected. The issue involves account linking to external identity providers.
What does an attacker need to exploit this issue?
An attacker does not need to authenticate or interact with the victim. They need to know the victim's login name and have an external IdP identity they can bind to that account.
Are identify-only Login V2 sessions affected?
Yes. The vulnerable account-linking behavior includes identify-only Login V2 sessions, as well as the User Service V2 AddIDPLink endpoint.
What is the impact after a successful link is created?
The attacker can sign in using their own linked external IdP identity as the victim. This results in account takeover and can affect confidentiality, integrity, and availability.