CVE-2026-105215: ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

Published Oct 4, 2026
·
Updated

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

Affected Software

1 affected component
ZITADEL ZITADEL<3.4.14, >=4.0.0<4.16.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ZITADEL to a version that resolves this vulnerability.

    Fixed in 3.4.14
  2. Upgrade

    Upgrade ZITADEL to a version that resolves this vulnerability.

    Fixed in 4.16.2

Event History

Oct 4, 2026
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using the hosted Login V1 UI are affected if they run a version before 3.4.14, or a 4.x version before 4.16.2. The vulnerable flow is the external-account-not-found registration endpoint.

2

What does an attacker need to exploit this issue?

The attacker does not need authentication or user interaction. They need to submit forged IDPConfigID and ExternalUserID values to create an account bound to the targeted victim's external IdP identity.

3

What is the practical impact on a victim?

An attacker can pre-create an account associated with the victim's external identity. When the victim later completes a legitimate external IdP login, that login signs into the attacker-created account.

4

How can I tell whether a suspected account takeover may be related to this flaw?

Investigate accounts created through the external-account-not-found registration flow and look for bindings involving forged or unexpected IDPConfigID and ExternalUserID values. Pay particular attention to accounts created before a victim's first genuine external IdP login.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203