OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105207

CRITICAL · CVSS 9.8 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

ZITADEL versions 3.0.0 through 3.4.15 and 4.0.0 prior to 4.17.3 are vulnerable due to improper verification of user account links with external identity providers, allowing unauthenticated attackers to associate their own identity with a victim's account using just the victim's login name. This critical vulnerability can lead to account takeover, enabling attackers to impersonate victims and access sensitive information. Organizations using affected versions should prioritize patching this vulnerability to safeguard user accounts and prevent unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105207
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%

Original NVD Description

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.