Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in ZITADEL, an identity and access management solution, allows unauthenticated attackers to link their own external identity provider to a victim's account by knowing their login name. This could enable an attacker to impersonate the victim and gain unauthorized access.
- Unauthenticated attackers can link external identities to user accounts.
- This allows unauthorized account takeover via identity provider linking.
- Confirm if ZITADEL is in use and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker knowing a victim's login name can link their own external identity provider to the victim's ZITADEL account without proper verification. This allows the attacker to then log in as the victim, potentially leading to a full account takeover. The vulnerability exists in specific versions of ZITADEL's user account linking and login functionalities.
- Unauthenticated attacker with victim's login name.
- Linking own external identity to victim's account.
- Account takeover and unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
The vulnerability could allow an unauthenticated attacker to impersonate any user by linking their own external identity provider to the victim's account without proper verification. This could occur when the system creates links between user accounts and external identity providers, even during identify-only login sessions, or through a specific API endpoint.
- User accounts could be compromised.
- Attacker binds own external identity to victim account.
- Unauthorized access to user accounts.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for identity and access management, application security, and the ZITADEL platform should prioritize this critical vulnerability. The immediate first step is to inventory all ZITADEL instances, determine their exposure, and identify business-critical deployments. Following this, accountable owners must be found to plan a risk-based remediation strategy.
- Ownership: Identity and Access Management team.
- Verify first: External access to vulnerable endpoints.
- Action: Plan ZITADEL version upgrades.