PatchSiren cyber security CVE debrief
CVE-2026-105214 zitadel CVE debrief
A server-side request forgery vulnerability exists in Zitadel before version 4.16.2. This vulnerability allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.Get instead of the protected client, enabling attackers to register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
- Vendor
- zitadel
- Product
- Unknown
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for Zitadel deployments should assess exposure and verify versions. Network administrators and security teams should also be aware of potential internal network scanning risks.
Why it matters
CVE-2026-105214 is a server-side request forgery vulnerability in Zitadel before 4.16.2. Defenders should verify versions, restrict internal resource access, and monitor for suspicious activity. The vulnerability allows attackers to scan internal networks, but exact impact and scope require further verification.
- Potential internal network mapping
- Port scanning risks from malicious domains
- Verification of Zitadel version required
- Possible exploitation of internal resources
Technical summary
The vulnerability exists due to the use of Go's default http.Get for challenge fetch instead of a protected client. This allows attackers to register domains that redirect to internal or cloud metadata addresses, enabling port scanning and internal network mapping. The issue affects Zitadel before version 4.16.2, and defenders should prioritize verifying versions and restricting internal resource access to mitigate potential risks. Affected deployments should be identified, and owners assigned for follow-up to ensure proper remediation.
Defensive priority
Defenders should prioritize verifying Zitadel versions and restricting internal resource access.
Recommended defensive actions
- Verify Zitadel version and ensure it is 4.16.2 or later
- Restrict access to internal resources
- Monitor for suspicious network activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the exact scope of affected versions and potential impact requires further verification from official sources. Defenders should verify Zitadel versions, assess exposure, and monitor for suspicious activity related to internal network scanning and port mapping. Official sources indicate a server-side request forgery vulnerability exists, allowing attackers to request internal resources through organization domain HTTP verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105214 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105214
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105214 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105214
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/zitadel/zitadel/security/advisories/GHSA-93hm-8q29-c8cr
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/zitadel-before-4.16.2-ssrf-via-organization-domain-http-verification
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.