<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ZITADEL (4.x &lt; 4.17.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/zitadel-4.x--4.17.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 16:53:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/zitadel-4.x--4.17.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in ZITADEL Identity Provider</title><link>https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/</link><pubDate>Sun, 04 Oct 2026 16:53:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-zitadel-auth-bypass/</guid><description>ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 are vulnerable to an authentication bypass via the AddIDPLink endpoint, allowing unauthenticated attackers to link malicious external IdP identities to victim accounts.</description><content:encoded><![CDATA[<p>ZITADEL identity management software contains a critical authentication bypass vulnerability (CVE-2026-105207) affecting versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2. The vulnerability exists within the User Service V2 AddIDPLink endpoint and certain Login V2 session flows. The software fails to verify primary authentication factors or caller permissions when establishing links between local user accounts and external identity providers (IdPs). An unauthenticated attacker who knows a target user's login name can exploit this by binding their own controlled external IdP identity to the victim's account. Once the link is established, the attacker can leverage the external IdP to authenticate as the victim, effectively bypassing standard password or MFA requirements. This issue is particularly severe as it allows for full account takeover without user interaction or prior knowledge of the victim's password.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain unauthorized access to any user account within the affected ZITADEL instance. This may lead to total account compromise, exfiltration of sensitive user data, unauthorized access to downstream applications integrated with the identity provider, and potential escalation of privileges depending on the target user's roles within the ZITADEL platform.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade ZITADEL installations immediately to version 3.4.16 or 4.17.3 to address CVE-2026-105207.</li>
<li>Audit existing external IdP links within the ZITADEL administrative console to identify any unauthorized or suspicious bindings created during the window of vulnerability.</li>
<li>Review web server access logs for repeated requests to the User Service V2 AddIDPLink endpoint from unrecognized or anomalous source IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-105207</category><category>identity-management</category><category>web-application</category><category>vulnerability</category><category>cve-2026-105213</category><category>cloud</category></item></channel></rss>