CVE-2026-105215
published 2026-10-04CVE-2026-105215: ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration…
PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.34%
25.2th percentile
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zitadel | zitadel | < 4.16.2 | 4.16.2 |
| zitadel | zitadel | < 3.4.14 | 3.4.14 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external i
ghsa_unreviewed·2026-10-04
CVE-2026-105215 [CRITICAL] CWE-290 ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external i
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
VulDB
Zitadel up to 3.4.13/4.16.1 Registration Endpoint IDPConfigID/ExternalUserID improper authentication (EUVD-2026-92108)
vuldb·2026-10-04·CVSS 9.1
CVE-2026-105215 [CRITICAL] Zitadel up to 3.4.13/4.16.1 Registration Endpoint IDPConfigID/ExternalUserID improper authentication (EUVD-2026-92108)
A vulnerability classified as critical was found in Zitadel up to 3.4.13/4.16.1. Affected is an unknown function of the component Registration Endpoint. Executing a manipulation of the argument IDPConfigID/ExternalUserID can lead to improper authentication.
The identification of this vulnerability is CVE-2026-105215. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-04
Published