CVE-2026-105209 PUBLISHED

ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment

Assigner: VulnCheck
Reserved: 04.10.2026 Published: 04.10.2026 Updated: 04.10.2026

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

Product Status

Vendor zitadel
Product zitadel
Versions Default: unaffected
  • affected from 0 to 4.17.1 (excl.)
  • Version 4.17.1 is unaffected
Vendor zitadel
Product zitadel
Versions Default: unaffected
  • affected from 0 to 3.4.15 (excl.)
  • Version 3.4.15 is unaffected

Credits

  • rud reporter
  • rz1027 reporter
  • lyhtheori reporter
  • AdamKorcz reporter
  • IAM-marco finder
  • grvijayan finder

References

Problem Types

  • Missing Authorization CWE