These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-105215 is a critical authentication bypass vulnerability in ZITADEL, a popular open-source identity and access management platform. The vulnerability affects ZITADEL versions before 3.4.14 and 4.x before 4.16.2. An unauthenticated attacker can exploit this vulnerability by submitting forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity. W [truncated]
CVE-2026-105214 is a server-side request forgery vulnerability in Zitadel before version 4.16.2. Attackers can exploit this vulnerability to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, allowing attackers to register domains that redirect to loopback, internal, or cloud metadata add [truncated]
CVE-2026-105213 is a high-severity vulnerability in ZITADEL 4.x before 4.17.1, allowing users from deactivated organizations to authenticate using Login V2. This occurs because the system verifies only the individual user's status, not the organization's inactive state. The vulnerability was published on 2026-10-04T15:16:32.687Z. Defenders should assess exposure and verify authentication configurations, p [truncated]
CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. This vulnerability allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA). The vulnerability is caused by the acceptance of passkey or other authenticator enrollment on identi [truncated]
CVE-2026-105211 is a critical authentication bypass vulnerability in ZITADEL before version 4.17.1. The vulnerability allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including admi [truncated]
CVE-2026-105210 is a high-severity vulnerability in ZITADEL's hosted Login V1 UI, allowing attackers to enroll arbitrary second-factor authentication methods and enumerate users. This issue affects ZITADEL versions 3.x before 3.4.15 and 4.x before 4.17.1. The vulnerability enables attackers to enroll TOTP, OTP-SMS, OTP-Email, or U2F factors without primary factor verification, leading to potential authent [truncated]
CVE-2026-105209 is a critical improper authorization vulnerability in ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. This vulnerability allows for potential account takeovers and unauthorized access [truncated]
CVE-2026-105208 debrief based on the supplied source corpus. The CVE record was published on 2026-10-04T15:16:31.843Z and has not been modified since then. This high-severity vulnerability in ZITADEL allows authenticated users to tamper with their own IdP intent tokens, potentially leading to session hijacking. Defenders responsible for ZITADEL deployments, particularly those using versions 4.x before 4.1 [truncated]
CVE-2026-105207 debrief based on the supplied source corpus. ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim. Defender [truncated]
CVE-2026-105206 is a medium-severity vulnerability affecting ZITADEL versions 3.0.0 through 3.4.15 and 4.x before 4.17.3. The vulnerability is caused by an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. This allows an authenticated member holding org-scoped user.read to query GET /v2/user [truncated]
PatchSiren debrief for CVE-2026-85056: ZITADEL open source identity management platform vulnerability allows reused browser sessions without verifying second factors, fixed in version 4.16.1. This issue affects ZITADEL Login V2, where a browser session is created after password verification and can be reused for later authentication requests without verifying a user's enrolled TOTP, OTP, or U2F second fac [truncated]
A high-severity vulnerability was found in ZITADEL's OAuth2 Token Exchange endpoint. Prior to version 4.15.3, the endpoint did not verify that the subject token belonged to the requesting client or that requested scopes remained within the original token's scopes. This allowed a low-privilege token to be exchanged for elevated permissions at another application. The vulnerability has been addressed in ver [truncated]
CVE-2026-56667 is a HIGH severity vulnerability in ZITADEL's Login V2 OIDC and SAML. Prior to version 4.15.3, the platform's FailedPrecondition error paths return loginSettings.defaultRedirectUri to router.push without applying the isSafeRedirectUri check. This allows an organization or instance administrator to store a javascript or data URI that can execute in a user's browser when an affected login err [truncated]
A medium-severity vulnerability was found in ZITADEL, an open-source identity management platform. The external identity provider handler does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3. The vulnerabil [truncated]
A vulnerability was found in ZITADEL, an open source identity management platform, affecting versions from 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1. The issue lies in the external JWT Identity Provider validation, where the system skips expiration handling when an incoming token omits the exp claim. This allows a token from a trusted issuer to be treated as valid without an automatic e [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T18:16:23.890Z and has not been modified since then. ZITADEL, an open-source identity management platform, has a vulnerability in its external JWT Identity Provider validation. The vulnerability allows arbitrarily old tokens from a trusted issuer to pass authentication when an incoming token omits [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T18:16:23.637Z and has not been modified since then. ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows failed to verify the requesting client, allowing intercepted grants or refresh tokens to be exchanged under a different client. This issue is fixed in versions 3.4.12 a [truncated]
A vulnerability was found in ZITADEL, an open-source identity management platform, affecting versions from 4.0.0-rc.1 through 4.15.1. The issue lies in the inconsistent validation of user-defined URLs against protected denylist handling in HTTP notification channels, OIDC BackChannel Logout, and SAML metadata URL fetches. This allows server-side requests to loopback, internal IP, link-local, or redirected [truncated]
A LOW-severity vulnerability was found in ZITADEL, an open-source identity management platform. The event store validation issue could retain the original resource owner for a deleted user identifier, potentially exposing users to unintended organization administrators. This issue is fixed in version 4.15.2. Administrators of ZITADEL installations, especially those with multiple organizations and user man [truncated]
A vulnerability was found in ZITADEL, an open-source identity management platform. The external JWT Identity Provider does not validate the audience (aud) claim of a token, allowing a validly signed token from a trusted issuer for another relying party to be accepted. This issue was fixed in versions 3.4.12 and 4.15.2. The vulnerability exists due to insufficient validation of the audience claim in JWT to [truncated]