
🚨 CVE-2026-105207 (CVSS 9.8 Critical) ZITADEL contains a flaw in its IdP linking endpoint, allowing unauthenticated attackers knowing a victim's login name to bind their own IdP identity and hijack the account. https://www.thehackerwire.com/vulnerability/CVE-2026-105207/ https://t.co/8gNkTj5uWy





