CVE-2026-105208: ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idpintents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are ZITADEL 4.x before 4.17.3 and ZITADEL 3.x through 3.4.15. The issue involves external identity-provider login intents and the /v2/idp_intents or /v2/sessions endpoints.
What does an attacker need to exploit this issue?
The attacker must be an authenticated user and must be able to modify their own IdP intent token. They also need to predict a victim's in-flight intent identifier and win a timing race against the victim's external login flow.
What is the impact if exploitation succeeds?
An attacker may steal the victim's identity-provider tokens or hijack the victim's session. The published vector indicates high confidentiality and integrity impact, with no availability impact.