CVE-2026-105215 PUBLISHED

ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

Assigner: VulnCheck
Reserved: 04.10.2026 Published: 04.10.2026 Updated: 05.10.2026

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor zitadel
Product zitadel
Versions Default: unaffected
  • affected from 0 to 4.16.2 (excl.)
  • Version 4.16.2 is unaffected
Vendor zitadel
Product zitadel
Versions Default: unaffected
  • affected from 0 to 3.4.14 (excl.)
  • Version 3.4.14 is unaffected

Credits

  • Ibonok reporter
  • livio-a finder
  • IAM-marco coordinator
  • AdamKorcz reporter

References

Problem Types

  • Authentication Bypass by Spoofing CWE