Overview
A critical authentication flaw has been disclosed in ZITADEL, the open-source identity and access management (IAM) platform used by organizations to centralize login, single sign-on, and user management. Tracked as CVE-2026-105207 with a maximum-severity CVSS score of 9.8, the vulnerability allows an unauthenticated attacker who merely knows a victim's login name to bind their own external identity provider (IdP) account to that victim's ZITADEL account — and then sign in as them.
The flaw affects identify-only Login V2 sessions and the User Service V2 AddIDPLink endpoint, where ZITADEL creates a link between a local user account and an external IdP identity without verifying a primary authentication factor or checking the caller's permission to perform the link.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105207 |
| Severity | Critical (CVSS 9.8) |
| CWE | CWE-306 — Missing Authentication for Critical Function |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Full account takeover |
| Affected Versions | 3.0.0 – 3.4.15, 4.0.0 before 4.17.3 |
| Fixed Versions | 3.4.15, 4.17.3 |
How It Works
ZITADEL's Login V2 flow supports "identify-only" sessions, where a user is identified (e.g., by username) before a primary authentication factor such as a password or passkey is verified. The AddIDPLink endpoint in the User Service V2 API is meant to let an already-authenticated user attach an external identity provider — such as a corporate SSO or social login — to their own account.
The vulnerability exists because ZITADEL does not verify that the caller has actually completed a primary factor, nor does it confirm the caller is authorized to modify the target account's IdP links. An attacker who knows (or guesses) a victim's login name can open an identify-only session for that account and call AddIDPLink to bind an external identity they control to the victim's ZITADEL user record. From that point, the attacker can authenticate through their own external IdP and be logged in as the victim — with no password, passkey, or second factor ever required.
Impact Assessment
Who Is At Risk
Any organization running a self-hosted ZITADEL instance in the affected version ranges (3.0.0–3.4.15 or 4.0.0 before 4.17.3) with external identity providers configured is vulnerable, including deployments that:
- Use ZITADEL as a central IAM/SSO provider for internal or customer-facing applications
- Allow self-service linking of external IdPs (Google, Microsoft, SAML, OIDC providers) to user accounts
- Expose the User Service V2 API or Login V2 flow to the public internet
Potential Attack Chains
- Account Identification — Attacker determines a target's login name (often an email address, frequently guessable or harvested from breaches/OSINT)
- Session Initiation — Attacker opens an identify-only Login V2 session for the target account without needing credentials
- Unverified IdP Binding — Attacker calls
AddIDPLinkto attach their own external IdP identity to the victim's account - Full Takeover — Attacker signs in via their external IdP and is authenticated as the victim, inheriting all of that account's permissions and access
Because ZITADEL is frequently deployed as the single point of truth for authentication across an organization's application portfolio, a successful account takeover here can cascade into every downstream service relying on ZITADEL for SSO.
Mitigation
Immediate Actions
- Upgrade immediately to ZITADEL 4.17.3 (4.x branch) or 3.4.15 (3.x branch), which contain the fix
- Audit recent IdP link events for accounts of interest (administrators, privileged service accounts) to check for unauthorized or unexpected external identity bindings created before patching
- Review and revoke any suspicious IdP links discovered during the audit
- Where immediate patching isn't possible, consider temporarily disabling self-service IdP linking and identify-only Login V2 sessions until the upgrade is complete
Detection Opportunities
- Query ZITADEL audit logs for
AddIDPLinkevents that do not correspond to a verified, authenticated session - Look for IdP links created in rapid succession across multiple accounts, which may indicate automated exploitation
- Monitor for logins via external IdPs that are new or unexpected for a given account
Defence-in-Depth
- Enforce multi-factor authentication on all accounts, particularly administrative ones, to limit the blast radius of authentication-layer flaws
- Restrict administrative and sensitive API access to trusted network ranges where feasible
- Regularly review configured external identity providers and remove unused or legacy IdP integrations
Discovery & Disclosure
The vulnerability was identified and reported by Lucas Dodson of Intigriti Labs and Adam Korczynski of Ada Logics. It is tracked upstream as GHSA-g8gj-gq47-xgf4. As of publication, CVE-2026-105207 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public proof-of-concept exploit has been observed, but given the unauthenticated, zero-interaction attack path, defenders should treat patching as urgent rather than wait for confirmed in-the-wild exploitation.