Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered. | |
| Title | ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:01.420Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105206
No data.
Status : Deferred
Published: 2026-10-04T15:16:31.517
Modified: 2026-10-04T15:16:31.627
Link: CVE-2026-105206
No data.
OpenCVE Enrichment
Updated: 2026-10-04T19:30:05Z
-
CWE-863
Incorrect Authorization