Sceawere

Vulnerability Detail

CVE-2026-105215UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ZITADEL Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
5h ago
Vendor
zitadel
Product
zitadel
Attack Type
Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-04T15:16:32.993Z",
  "pubdate": "2026-10-04T15:16:32.993Z",
  "executiveSummary": "ZITADEL versions before 3.4.14 and 4.x before 4.16.2 are affected by a critical authentication bypass vulnerability in the hosted Login V1 UI.\nThe vulnerability arises from an insecure implementation of the 'external account not found' registration endpoint, which improperly trusts client-supplied external identity parameters.\nThis flaw allows unauthenticated remote attackers to perform an identity pre-binding attack, where a malicious actor links a ZITADEL account to a victim’s legitimate third-party Identity Provider (IdP) identifier.\nThe risk implication is significant, as it facilitates account takeover or unauthorized access to user accounts upon the victim's subsequent genuine login attempt.\nExploitation does not require prior authentication and relies on the ability to forge external identity fields (IDPConfigID and ExternalUserID) during the registration process.\nOrganizations using the affected ZITADEL versions are exposed to unauthorized account association, potentially compromising the integrity of user identity management and authentication workflows.\nImmediate patching to the specified secure versions is required to prevent unauthorized account access and potential cross-platform identity spoofing.",
  "technicalDetails": "The vulnerability exists within the ZITADEL hosted Login V1 UI component, specifically affecting the registration workflow triggered when an external account is not found.\nThe root cause is an improper trust relationship established between the application and the client-side inputs provided during the registration callback flow. The system fails to cryptographically verify or statefully confirm that the provided Identity Provider (IdP) assertions were generated by a legitimate IdP callback.\nIn a standard secure implementation, the registration process for an external account should only proceed following a validated callback containing cryptographically signed tokens or claims directly from the configured IdP.\nHowever, in the vulnerable versions, the endpoint accepts user-supplied identifiers—specifically 'IDPConfigID' and 'ExternalUserID'—without validating these fields against an active, pending authentication state.\nThe attack flow proceeds as follows: An attacker identifies the target's external identity configuration and the desired target user account context. The attacker then crafts a malicious HTTP request to the registration endpoint, supplying the target 'IDPConfigID' (representing the target IdP) and a spoofed 'ExternalUserID' (the victim's unique identifier within that IdP).\nBecause the server lacks a mandatory check for a completed, server-side verified IdP handshake, it processes this input as a trusted association. This effectively pre-creates a user record in the ZITADEL database that maps the attacker's chosen account to the victim's external identity.\nWhen the victim subsequently attempts to log in using their genuine external IdP credentials, ZITADEL performs a lookup against the established records. Because the attacker has already pre-bound the account, the victim’s session is associated with the identity record pre-configured by the attacker, leading to an authentication bypass where the victim is logged into the session state determined by the malicious binding.\nThe exposure is network-based, as the endpoint is exposed via the Login V1 UI, and the requirements for exploitation involve minimal technical sophistication once the parameter format is identified.\nThe post-exploitation impact allows attackers to influence the session mapping of legitimate users, which may lead to total account takeover or unauthorized access to sensitive application data associated with the target external identity, depending on the victim's privileges within the ZITADEL instance."
}
CVE-2026-105215: ZITADEL Authentication Bypass Vulnerability (CRITICAL Severity, CVSS: 9.1) | Sceawere