Product
ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 are vulnerable to an authentication bypass via the AddIDPLink endpoint, allowing unauthenticated attackers to link malicious external IdP identities to victim accounts.