Skip to content
Threat Feed
critical advisory

Authentication Bypass in ZITADEL Identity Provider

ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 are vulnerable to an authentication bypass via the AddIDPLink endpoint, allowing unauthenticated attackers to link malicious external IdP identities to victim accounts.

CVE search metadata

CVE search record: CVE-2026-105207. Severity: critical. CVSS: 9.8. KEV: no. Product: ZITADEL (3.0.0 through 3.4.15), ZITADEL (4.0.0 through 4.17.2), ZITADEL (< 3.4.14, 4.x < 4.16.2), ZITADEL (4.x before 4.17.3, 3.x through 3.4.15), ZITADEL (< 4.17.1), ZITADEL (3.x < 3.4.15), ZITADEL (4.x < 4.17.1). Brief: Authentication Bypass in ZITADEL Identity Provider. Brief link: https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/

What's new

  • 1. added coverage for ZITADEL (3.x < 3.4.15) +1 products Oct 4, 20:54 via nvd
  • 2. added coverage for ZITADEL (< 4.17.1) Oct 4, 16:54 via nvd
  • 3. added coverage for ZITADEL (4.x before 4.17.3, 3.x through 3.4.15) Oct 4, 16:53 via nvd
  • 4. added coverage for ZITADEL (< 3.4.14, 4.x < 4.16.2) Oct 4, 16:53 via nvd

ZITADEL identity management software contains a critical authentication bypass vulnerability (CVE-2026-105207) affecting versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. The vulnerability exists within the User Service V2 AddIDPLink endpoint and certain Login V2 session flows. The software fails to verify primary authentication factors or caller permissions when establishing links between local user accounts and external identity providers (IdPs). An unauthenticated attacker who knows a target user's login name can exploit this by binding their own controlled external IdP identity to the victim's account. Once the link is established, the attacker can leverage the external IdP to authenticate as the victim, effectively bypassing standard password or MFA requirements. This issue is particularly severe as it allows for full account takeover without user interaction or prior knowledge of the victim's password.

Impact

Successful exploitation allows unauthenticated attackers to gain unauthorized access to any user account within the affected ZITADEL instance. This may lead to total account compromise, exfiltration of sensitive user data, unauthorized access to downstream applications integrated with the identity provider, and potential escalation of privileges depending on the target user's roles within the ZITADEL platform.

Recommendation

  • Upgrade ZITADEL installations immediately to version 3.4.16 or 4.17.3 to address CVE-2026-105207.
  • Audit existing external IdP links within the ZITADEL administrative console to identify any unauthorized or suspicious bindings created during the window of vulnerability.
  • Review web server access logs for repeated requests to the User Service V2 AddIDPLink endpoint from unrecognized or anomalous source IP addresses.

Immediate actions

Upgrade ZITADEL to 4.17.3 or 3.4.16

IT Operations 24h

Threat Hunt

Analyze logs for high volume of calls to the AddIDPLink API endpoint

T1133 high medium confidence hunt now

Data: webserver access logs

Mitigations

Upgrade to fixed versions

immediate IT Operations

CVE-2026-105207