Redpacketsecurity ZITADEL Identity Provider Vulnerabilities Expose Critical Authentication Flaws
Article Content
- •ZITADEL disclosed 15 vulnerabilities, including critical authentication bypass flaws.
- •CVE-2026-105209 and CVE-2026-105215 allow unauthenticated account takeover and pre-hijacking.
- •The 3.x version line is end-of-life, leaving unpatched systems permanently exposed.
Between October 2 and October 5, 2026, a cluster of vulnerabilities affecting the ZITADEL identity provider was disclosed, revealing 15 CVEs, including critical flaws that allow unauthenticated account takeover and bypass of multi-factor authentication (MFA). The most severe vulnerabilities include CVE-2026-105209 (CVSS 9.6), enabling cross-organization passkey enrollment, and CVE-2026-105215 (CVSS 9.1), allowing unauthenticated account pre-hijacking. These vulnerabilities stem from a failure to verify the binding between credentials and claimed identities, exposing systems that rely on ZITADEL for authentication. The 3.x version line reached end-of-life on August 31, 2026, leaving deployments vulnerable. Active exploitation of these vulnerabilities is under investigation, with some reports indicating potential exploitation in the wild. Organizations using ZITADEL for user authentication are urged to assess their deployments and apply patches immediately.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Zitadel and CVE-2026-105206 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of ZITADEL are affected?
Is there evidence of exploitation in the wild?
What immediate actions should organizations take?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…