CVE-2026-105207

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Peaked 2d ago at 3 mentions (2026-10-04); latest day: 2
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-10-04: 3Mentions · 2026-10-05: 1Mentions · 2026-10-06: 210-0410-0510-06
Referenced assets5 URLs
Full discourse6 posts
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-105207 (CVSS 9.8 Critical) ZITADEL contains a flaw in its IdP linking endpoint, allowing unauthenticated attackers knowing a victim's login name to bind their own IdP identity and hijack the account. https://www.thehackerwire.com/vulnerability/CVE-2026-105207/ https://t.co/8gNkTj5uWy

    0001056
    175 followersView on X
  • 0xAppSec@0xAppSec

    ZITADEL linked external identity providers to accounts without checking a primary factor. Knowing a login name was enough to sign in as the victim. CVE-2026-105207. Adding a sign-in method is a sign-in. Any endpoint that attaches a passkey or IdP must demand an existing factor.

    0000011
    34 followersView on X
  • takenaka hiroya@Joe_Biden_ja

    ZITADEL の外部IdP連携に、ログイン名を知るだけで未認証のままアカウントを乗っ取れる欠陥(CVE-2026-105207)。4.17.3 で修正、3.x は修正版なし。対象版と対処を整理しました。 https://cve.autoarticles.net/cve/CVE-2026-105207

    0000034
    555 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen Kritische ZITADEL-Schwachstellen ermöglichen Kontoübernahme über Login und IdP-Verknüpfung #cve2026105207 #cve2026105209 #cve2026105211 #cve2026105215 #identityprovider #loginv1 #loginv2 #zitadel https://cybersecurity-news.de/zitadel-kritische-schwachstellen-kontouebernahme-cve-2026-105207-cve-2026-105209-cve-2026-105211-cve-2026-105215

    0000026
    14 followersView on X
  • CVE@CVEnew

    CVE-2026-105207 ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the c… https://www.cve.org/CVERecord?id=CVE-2026-105207

    000001.7K
    58.1K followersView on X
  • Severity Daily@severitydaily

    ZITADEL's 3.x branch went end-of-life four days before the advisory naming it affected by an unauthenticated account takeover. The CVE arrived today. No fix for 3.x, no exploitation reported. https://severitydaily.com/zitadel-cve-2026-105207-4-17-3-fix-4-19-4-affected-3-x-no-patch-eol/

    0000025
    32 followersView on X

Explore more