Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in ZITADEL's identity and access management system that could allow unauthorized account takeover. The flaw lies in how the system handles passkey and passwordless enrollment codes, where an attacker with user-write permissions in one organization could potentially register their own authenticator to gain control of an account in a different organization within the same instance. The main concern is confirming relevance and exposure, as this could impact user accounts and the integrity of identity management if exploited.
- Improper authorization allows account takeover.
- Leadership should remember this affects user account security.
- Confirm relevance and exposure for affected accounts.
Attack Path
How an attacker could exploit the issue
An attacker, starting with user-write permissions in one organization, can exploit this vulnerability by manipulating the `x-zitadel-orgid` header when issuing enrollment codes. This allows them to obtain a code for a user in a different organization. By then registering their own authenticator using this code, the attacker can take over the target user's account, effectively hijacking their identity within the ZITADEL instance.
- Attacker needs write permission.
- Triggered by manipulated header during code issuance.
- Leads to cross-organization account takeover.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an attacker with user-write permissions in one organization could potentially register their own authenticator to take over user accounts in a different organization on the same ZITADEL instance by obtaining an enrollment code through an improperly checked organization ID.
- User accounts in other organizations.
- Obtain enrollment code for another organization.
- Unauthorized account access.
Operational Fix
Recommended remediation, mitigation, and detection steps
The ZITADEL platform owner or the identity and access management (IAM) platform team is likely responsible for addressing this vulnerability, as it affects user authentication and account takeover. The first practical step is to identify all ZITADEL instances, confirm their exposure and criticality, and determine the accountable owner before planning remediation.
- Identify ZITADEL instances and owners.
- Verify user write permissions and orgs.
- Plan targeted vendor coordination or upgrade.