Skip to content
ZITADEL Identity Provider Vulnerabilities Expose Critical Authentication Flaws

ZITADEL Identity Provider Vulnerabilities Expose Critical Authentication Flaws

First seen 5 Oct 2026, 17:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 17:06 UTC
  • •ZITADEL disclosed 15 vulnerabilities, including critical authentication bypass flaws.
  • •CVE-2026-105209 and CVE-2026-105215 allow unauthenticated account takeover and pre-hijacking.
  • •The 3.x version line is end-of-life, leaving unpatched systems permanently exposed.

Between October 2 and October 5, 2026, a cluster of vulnerabilities affecting the ZITADEL identity provider was disclosed, revealing 15 CVEs, including critical flaws that allow unauthenticated account takeover and bypass of multi-factor authentication (MFA). The most severe vulnerabilities include CVE-2026-105209 (CVSS 9.6), enabling cross-organization passkey enrollment, and CVE-2026-105215 (CVSS 9.1), allowing unauthenticated account pre-hijacking. These vulnerabilities stem from a failure to verify the binding between credentials and claimed identities, exposing systems that rely on ZITADEL for authentication. The 3.x version line reached end-of-life on August 31, 2026, leaving deployments vulnerable. Active exploitation of these vulnerabilities is under investigation, with some reports indicating potential exploitation in the wild. Organizations using ZITADEL for user authentication are urged to assess their deployments and apply patches immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-13
CVE-2026-73570 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
Vulnerabilities disclosed
A cluster of vulnerabilities affecting ZITADEL was disclosed, revealing critical flaws in authentication mechanisms.
Forkast.News
2026-10-03
CVE-2026-71885 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
Critical CVEs published
Multiple critical CVEs, including CVE-2026-105209 and CVE-2026-105215, were published, exposing serious authentication flaws.
Redpacketsecurity
2026-10-04
CVE-2026-105207 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-105210 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-105211 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-105215 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-105208 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
CVE-2026-105212 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (9)

Following this threat?

Track Zitadel and CVE-2026-105206 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of ZITADEL are affected?
ZITADEL versions 3.x before 3.4.14 and 4.x before 4.16.2 are affected by the disclosed vulnerabilities.
Is there evidence of exploitation in the wild?
Reports suggest potential active exploitation, but confirmation from major threat intelligence platforms is still pending.
What immediate actions should organizations take?
Organizations should assess their ZITADEL deployments, apply available patches, and monitor for unusual authentication activity.