Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into. | |
| Title | ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:07.389Z
Reserved: 2026-10-04T13:04:00.478Z
Link: CVE-2026-105215
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.993
Modified: 2026-10-04T15:16:33.107
Link: CVE-2026-105215
No data.
OpenCVE Enrichment
Updated: 2026-10-04T15:45:04Z
-
CWE-290
Authentication Bypass by Spoofing