PatchSiren

zitadel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL zitadel CVE published 2026-10-04

CVE-2026-105215

CVE-2026-105215 is a critical authentication bypass vulnerability in ZITADEL, a popular open-source identity and access management platform. The vulnerability affects ZITADEL versions before 3.4.14 and 4.x before 4.16.2. An unauthenticated attacker can exploit this vulnerability by submitting forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity. W [truncated]

LOW zitadel CVE published 2026-10-04

CVE-2026-105214

CVE-2026-105214 is a server-side request forgery vulnerability in Zitadel before version 4.16.2. Attackers can exploit this vulnerability to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, allowing attackers to register domains that redirect to loopback, internal, or cloud metadata add [truncated]

HIGH zitadel CVE published 2026-10-04

CVE-2026-105213

CVE-2026-105213 is a high-severity vulnerability in ZITADEL 4.x before 4.17.1, allowing users from deactivated organizations to authenticate using Login V2. This occurs because the system verifies only the individual user's status, not the organization's inactive state. The vulnerability was published on 2026-10-04T15:16:32.687Z. Defenders should assess exposure and verify authentication configurations, p [truncated]

HIGH zitadel CVE published 2026-10-04

CVE-2026-105212

CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. This vulnerability allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA). The vulnerability is caused by the acceptance of passkey or other authenticator enrollment on identi [truncated]

CRITICAL zitadel CVE published 2026-10-04

CVE-2026-105211

CVE-2026-105211 is a critical authentication bypass vulnerability in ZITADEL before version 4.17.1. The vulnerability allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including admi [truncated]

HIGH zitadel CVE published 2026-10-04

CVE-2026-105210

CVE-2026-105210 is a high-severity vulnerability in ZITADEL's hosted Login V1 UI, allowing attackers to enroll arbitrary second-factor authentication methods and enumerate users. This issue affects ZITADEL versions 3.x before 3.4.15 and 4.x before 4.17.1. The vulnerability enables attackers to enroll TOTP, OTP-SMS, OTP-Email, or U2F factors without primary factor verification, leading to potential authent [truncated]

CRITICAL zitadel CVE published 2026-10-04

CVE-2026-105209

CVE-2026-105209 is a critical improper authorization vulnerability in ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. This vulnerability allows for potential account takeovers and unauthorized access [truncated]

HIGH zitadel CVE published 2026-10-04

CVE-2026-105208

CVE-2026-105208 debrief based on the supplied source corpus. The CVE record was published on 2026-10-04T15:16:31.843Z and has not been modified since then. This high-severity vulnerability in ZITADEL allows authenticated users to tamper with their own IdP intent tokens, potentially leading to session hijacking. Defenders responsible for ZITADEL deployments, particularly those using versions 4.x before 4.1 [truncated]

CRITICAL zitadel CVE published 2026-10-04

CVE-2026-105207

CVE-2026-105207 debrief based on the supplied source corpus. ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim. Defender [truncated]

MEDIUM zitadel CVE published 2026-10-04

CVE-2026-105206

CVE-2026-105206 is a medium-severity vulnerability affecting ZITADEL versions 3.0.0 through 3.4.15 and 4.x before 4.17.3. The vulnerability is caused by an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. This allows an authenticated member holding org-scoped user.read to query GET /v2/user [truncated]

HIGH zitadel CVE published 2026-09-24

CVE-2026-85056

PatchSiren debrief for CVE-2026-85056: ZITADEL open source identity management platform vulnerability allows reused browser sessions without verifying second factors, fixed in version 4.16.1. This issue affects ZITADEL Login V2, where a browser session is created after password verification and can be reused for later authentication requests without verifying a user's enrolled TOTP, OTP, or U2F second fac [truncated]

HIGH zitadel CVE published 2026-07-10

CVE-2026-56668

A high-severity vulnerability was found in ZITADEL's OAuth2 Token Exchange endpoint. Prior to version 4.15.3, the endpoint did not verify that the subject token belonged to the requesting client or that requested scopes remained within the original token's scopes. This allowed a low-privilege token to be exchanged for elevated permissions at another application. The vulnerability has been addressed in ver [truncated]

HIGH zitadel CVE published 2026-07-10

CVE-2026-56667

CVE-2026-56667 is a HIGH severity vulnerability in ZITADEL's Login V2 OIDC and SAML. Prior to version 4.15.3, the platform's FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check. This allows an organization or instance administrator to store a javascript or data URI that can execute in a user's browser when an affected login err [truncated]

MEDIUM zitadel CVE published 2026-07-10

CVE-2026-56666

A medium-severity vulnerability was found in ZITADEL, an open-source identity management platform. The external identity provider handler does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3. The vulnerabil [truncated]

MEDIUM zitadel CVE published 2026-07-10

CVE-2026-56665

A vulnerability was found in ZITADEL, an open source identity management platform, affecting versions from 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1. The issue lies in the external JWT Identity Provider validation, where the system skips expiration handling when an incoming token omits the exp claim. This allows a token from a trusted issuer to be treated as valid without an automatic e [truncated]

MEDIUM zitadel CVE published 2026-07-10

CVE-2026-56664

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T18:16:23.890Z and has not been modified since then. ZITADEL, an open-source identity management platform, has a vulnerability in its external JWT Identity Provider validation. The vulnerability allows arbitrarily old tokens from a trusted issuer to pass authentication when an incoming token omits [truncated]

HIGH zitadel CVE published 2026-07-10

CVE-2026-55672

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T18:16:23.637Z and has not been modified since then. ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows failed to verify the requesting client, allowing intercepted grants or refresh tokens to be exchanged under a different client. This issue is fixed in versions 3.4.12 a [truncated]

LOW zitadel CVE published 2026-07-10

CVE-2026-55671

A vulnerability was found in ZITADEL, an open-source identity management platform, affecting versions from 4.0.0-rc.1 through 4.15.1. The issue lies in the inconsistent validation of user-defined URLs against protected denylist handling in HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches. This allows server-side requests to loopback, internal IP, link-local, or redirected [truncated]

LOW zitadel CVE published 2026-07-10

CVE-2026-55670

A LOW-severity vulnerability was found in ZITADEL, an open-source identity management platform. The event store validation issue could retain the original resource owner for a deleted user identifier, potentially exposing users to unintended organization administrators. This issue is fixed in version 4.15.2. Administrators of ZITADEL installations, especially those with multiple organizations and user man [truncated]

MEDIUM zitadel CVE published 2026-07-10

CVE-2026-55669

A vulnerability was found in ZITADEL, an open-source identity management platform. The external JWT Identity Provider does not validate the audience (aud) claim of a token, allowing a validly signed token from a trusted issuer for another relying party to be accepted. This issue was fixed in versions 3.4.12 and 4.15.2. The vulnerability exists due to insufficient validation of the audience claim in JWT to [truncated]