Authentication Bypass in ZITADEL Identity Provider
ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 are vulnerable to an authentication bypass via the AddIDPLink endpoint, allowing unauthenticated attackers to link malicious external IdP identities to victim accounts.
CVE search metadata
CVE search record: CVE-2026-105207. Severity: critical. CVSS: 9.8. KEV: no. Product: ZITADEL (3.0.0 through 3.4.15), ZITADEL (4.0.0 through 4.17.2), ZITADEL (< 3.4.14, 4.x < 4.16.2), ZITADEL (4.x before 4.17.3, 3.x through 3.4.15), ZITADEL (< 4.17.1), ZITADEL (3.x < 3.4.15), ZITADEL (4.x < 4.17.1). Brief: Authentication Bypass in ZITADEL Identity Provider. Brief link: https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/
What's new
- 1. added coverage for ZITADEL (3.x < 3.4.15) +1 products Oct 4, 20:54 via nvd
- 2. added coverage for ZITADEL (< 4.17.1) Oct 4, 16:54 via nvd
- 3. added coverage for ZITADEL (4.x before 4.17.3, 3.x through 3.4.15) Oct 4, 16:53 via nvd
- 4. added coverage for ZITADEL (< 3.4.14, 4.x < 4.16.2) Oct 4, 16:53 via nvd
ZITADEL identity management software contains a critical authentication bypass vulnerability (CVE-2026-105207) affecting versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. The vulnerability exists within the User Service V2 AddIDPLink endpoint and certain Login V2 session flows. The software fails to verify primary authentication factors or caller permissions when establishing links between local user accounts and external identity providers (IdPs). An unauthenticated attacker who knows a target user's login name can exploit this by binding their own controlled external IdP identity to the victim's account. Once the link is established, the attacker can leverage the external IdP to authenticate as the victim, effectively bypassing standard password or MFA requirements. This issue is particularly severe as it allows for full account takeover without user interaction or prior knowledge of the victim's password.
Impact
Successful exploitation allows unauthenticated attackers to gain unauthorized access to any user account within the affected ZITADEL instance. This may lead to total account compromise, exfiltration of sensitive user data, unauthorized access to downstream applications integrated with the identity provider, and potential escalation of privileges depending on the target user's roles within the ZITADEL platform.
Recommendation
- Upgrade ZITADEL installations immediately to version 3.4.16 or 4.17.3 to address CVE-2026-105207.
- Audit existing external IdP links within the ZITADEL administrative console to identify any unauthorized or suspicious bindings created during the window of vulnerability.
- Review web server access logs for repeated requests to the User Service V2 AddIDPLink endpoint from unrecognized or anomalous source IP addresses.
Immediate actions
Upgrade ZITADEL to 4.17.3 or 3.4.16
Threat Hunt
Analyze logs for high volume of calls to the AddIDPLink API endpoint
Data: webserver access logs
Mitigations
Upgrade to fixed versions
CVE-2026-105207