PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105214 zitadel CVE debrief

A server-side request forgery vulnerability exists in Zitadel before version 4.16.2. This vulnerability allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, enabling attackers to register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.

Vendor
zitadel
Product
Unknown
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for Zitadel deployments should assess exposure and verify versions. Network administrators and security teams should also be aware of potential internal network scanning risks.

Why it matters

CVE-2026-105214 is a server-side request forgery vulnerability in Zitadel before 4.16.2. Defenders should verify versions, restrict internal resource access, and monitor for suspicious activity. The vulnerability allows attackers to scan internal networks, but exact impact and scope require further verification.

  • Potential internal network mapping
  • Port scanning risks from malicious domains
  • Verification of Zitadel version required
  • Possible exploitation of internal resources

Technical summary

The vulnerability exists due to the use of Go's default http.Get for challenge fetch instead of a protected client. This allows attackers to register domains that redirect to internal or cloud metadata addresses, enabling port scanning and internal network mapping. The issue affects Zitadel before version 4.16.2, and defenders should prioritize verifying versions and restricting internal resource access to mitigate potential risks. Affected deployments should be identified, and owners assigned for follow-up to ensure proper remediation.

Defensive priority

Defenders should prioritize verifying Zitadel versions and restricting internal resource access.

Recommended defensive actions

  • Verify Zitadel version and ensure it is 4.16.2 or later
  • Restrict access to internal resources
  • Monitor for suspicious network activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the exact scope of affected versions and potential impact requires further verification from official sources. Defenders should verify Zitadel versions, assess exposure, and monitor for suspicious activity related to internal network scanning and port mapping. Official sources indicate a server-side request forgery vulnerability exists, allowing attackers to request internal resources through organization domain HTTP verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105214 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105214

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105214 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105214

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.