External risk intelligence

ZITADEL External Identity Linking Vulnerability Enables Account Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105207

ZITADEL is an identity and access management (IAM) solution designed to be a public-facing identity provider. The vulnerable endpoints relate to user authentication and external identity provider linking, which are services intended to be accessible to end users over the internet.

Missing Authentication

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in ZITADEL, an identity and access management solution, allows unauthenticated attackers to link their own external identity provider to a victim's account by knowing their login name. This could enable an attacker to impersonate the victim and gain unauthorized access.

  • Unauthenticated attackers can link external identities to user accounts.
  • This allows unauthorized account takeover via identity provider linking.
  • Confirm if ZITADEL is in use and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker knowing a victim's login name can link their own external identity provider to the victim's ZITADEL account without proper verification. This allows the attacker to then log in as the victim, potentially leading to a full account takeover. The vulnerability exists in specific versions of ZITADEL's user account linking and login functionalities.

  • Unauthenticated attacker with victim's login name.
  • Linking own external identity to victim's account.
  • Account takeover and unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

The vulnerability could allow an unauthenticated attacker to impersonate any user by linking their own external identity provider to the victim's account without proper verification. This could occur when the system creates links between user accounts and external identity providers, even during identify-only login sessions, or through a specific API endpoint.

  • User accounts could be compromised.
  • Attacker binds own external identity to victim account.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for identity and access management, application security, and the ZITADEL platform should prioritize this critical vulnerability. The immediate first step is to inventory all ZITADEL instances, determine their exposure, and identify business-critical deployments. Following this, accountable owners must be found to plan a risk-based remediation strategy.

  • Ownership: Identity and Access Management team.
  • Verify first: External access to vulnerable endpoints.
  • Action: Plan ZITADEL version upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZITADEL?

ZITADEL is an open-source identity and access management (IAM) solution. Organizations use it to centralize user authentication, manage identity lifecycles, and handle logins across their applications. By acting as a central identity provider, it simplifies how users sign in while giving administrators control over authentication policies and external identity integrations.

What does CWE-306 mean for CVE-2026-105207?

CWE-306 refers to a Missing Authentication for Critical Function. In the context of CVE-2026-105207, this means the software performs a sensitive security action—linking an external identity provider to a user account—without first confirming the identity of the person making the request or ensuring they have the necessary permissions to modify that account.

How does an attacker trigger this vulnerability?

An attacker needs only the victim's login name. By targeting specific API endpoints or session flows, the attacker can force the system to link their own external identity to the victim's account. This flaw does not require the attacker to compromise an existing password; normal, authenticated account activities are not required to initiate this unauthorized link.

Is my ZITADEL instance at risk?

According to Halo Surface Signal, ZITADEL is designed as a public-facing service, making instances exposed to the internet inherently more relevant for this vulnerability. If your ZITADEL deployment is reachable from the internet to support end-user logins, the risk is higher because the affected authentication and account-linking endpoints are intended to be accessible to users.

How should I respond to this vulnerability?

First, inventory all ZITADEL instances in your environment to identify which are running affected versions. Once you have a list of deployments, prioritize those that are internet-facing or hold sensitive user data. Finally, engage your identity management team to plan and execute an upgrade to a patched version, as this is the primary way to remediate the logic flaw.

References