CVE-2026-105215: ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZITADELto a version that resolves this vulnerability.Fixed in 3.4.14 - Upgrade
Upgrade
ZITADELto a version that resolves this vulnerability.Fixed in 4.16.2
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the hosted Login V1 UI are affected if they run a version before 3.4.14, or a 4.x version before 4.16.2. The vulnerable flow is the external-account-not-found registration endpoint.
What does an attacker need to exploit this issue?
The attacker does not need authentication or user interaction. They need to submit forged IDPConfigID and ExternalUserID values to create an account bound to the targeted victim's external IdP identity.
What is the practical impact on a victim?
An attacker can pre-create an account associated with the victim's external identity. When the victim later completes a legitimate external IdP login, that login signs into the attacker-created account.
How can I tell whether a suspected account takeover may be related to this flaw?
Investigate accounts created through the external-account-not-found registration flow and look for bindings involving forged or unexpected IDPConfigID and ExternalUserID values. Pay particular attention to accounts created before a victim's first genuine external IdP login.