Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. | |
| Title | ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:03.314Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105209
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.007
Modified: 2026-10-04T15:16:32.127
Link: CVE-2026-105209
No data.
OpenCVE Enrichment
Updated: 2026-10-04T16:30:16Z
-
CWE-862
Missing Authorization