{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/zitadel-3.x--3.4.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-105207"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZITADEL (3.0.0 through 3.4.15)","ZITADEL (4.0.0 through 4.17.2)","ZITADEL (\u003c 3.4.14, 4.x \u003c 4.16.2)","ZITADEL (4.x before 4.17.3, 3.x through 3.4.15)","ZITADEL (\u003c 4.17.1)","ZITADEL (3.x \u003c 3.4.15)","ZITADEL (4.x \u003c 4.17.1)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-105207","identity-management","web-application","vulnerability","cve-2026-105213","cloud"],"_cs_type":"advisory","_cs_vendors":["ZITADEL"],"content_html":"\u003cp\u003eZITADEL identity management software contains a critical authentication bypass vulnerability (CVE-2026-105207) affecting versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. The vulnerability exists within the User Service V2 AddIDPLink endpoint and certain Login V2 session flows. The software fails to verify primary authentication factors or caller permissions when establishing links between local user accounts and external identity providers (IdPs). An unauthenticated attacker who knows a target user's login name can exploit this by binding their own controlled external IdP identity to the victim's account. Once the link is established, the attacker can leverage the external IdP to authenticate as the victim, effectively bypassing standard password or MFA requirements. This issue is particularly severe as it allows for full account takeover without user interaction or prior knowledge of the victim's password.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to any user account within the affected ZITADEL instance. This may lead to total account compromise, exfiltration of sensitive user data, unauthorized access to downstream applications integrated with the identity provider, and potential escalation of privileges depending on the target user's roles within the ZITADEL platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade ZITADEL installations immediately to version 3.4.16 or 4.17.3 to address CVE-2026-105207.\u003c/li\u003e\n\u003cli\u003eAudit existing external IdP links within the ZITADEL administrative console to identify any unauthorized or suspicious bindings created during the window of vulnerability.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for repeated requests to the User Service V2 AddIDPLink endpoint from unrecognized or anomalous source IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T20:54:12Z","date_published":"2026-10-04T16:53:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/","summary":"ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 are vulnerable to an authentication bypass via the AddIDPLink endpoint, allowing unauthenticated attackers to link malicious external IdP identities to victim accounts.","title":"Authentication Bypass in ZITADEL Identity Provider","url":"https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - ZITADEL (3.x \u003c 3.4.15)","version":"https://jsonfeed.org/version/1.1"}