Skip to content
CVE-2026-105209

CVE-2026-105209

github.com • October 5, 2026

ZITADEL lets an administrator start passkey or passwordless enrollment for another user by issuing a one-time enrollment link (or code). When that link was requested, ZITADEL did not verify that the caller was authorized in the organization that owns the target user — it only checked the caller's permission in the organization named in the x-zitadel-orgid request header. As a result, an administrator of one organization could issue an enrollment code for a user in any other organization on the same instance.

An attacker who can manage users in one organization (or otherwise holds a user-write permission in any single organization) can:

Request a passkey or passwordless enrollment code for a user in a different organization , including the variants that return the code directly in the API response.

Enroll an attacker-controlled authenticator on the victim's account and take it over , because the enrollment code lets a new credential be added without any further action or authentication by the victim.

This does not expose the victim's existing credentials, and it does not affect the login flow that redeems an enrollment code — that flow is designed to accept the code as a bearer token. The only flaw is the missing authorization check when the code is created .

Scope note: The flaw affects the passkey and passwordless enrollment-link capability across the affected APIs. This is a cross-organization authorization flaw within a single instance and does not cross instance boundaries.

4.x: 4.0.0 through 4.17.0 (including RC versions)

3.x: 3.0.0 through 3.4.14 (including RC versions)

The vulnerability has been addressed in the latest releases. Issuing a passkey or passwordless enrollment code now verifies the caller's permission against the organization that owns the target user before the code is created.

4.x : Upgrade to $\ge$ 4.17.1

3.x : Upgrade to $\ge$ 3.4.15

The recommended solution is to upgrade to a patched version. There is no configuration that fully closes this gap on unpatched versions.

If you have any questions or this advisory, please email us at [email protected]

For reporting the vulnerability.

Extracted Entities

Domains (1)

Email Addresses (1)