Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in ZITADEL's hosted Login UI, specifically affecting how external account registrations are handled. This flaw could allow unauthenticated attackers to bypass standard authentication processes by pre-creating accounts linked to a victim's external identity provider. Subsequent legitimate logins by the victim could then inadvertently associate their account with the attacker's pre-created entry.
- Authentication bypass allows account pre-hijacking.
- Affects public-facing login and registration processes.
- Confirm relevance and potential exposure to understand impact.
Attack Path
How an attacker could exploit the issue
An attacker can bypass standard login procedures by exploiting a flaw in the hosted Login UI's registration endpoint. This allows them to pre-create an account linked to a victim's external identity provider. When the victim later attempts to log in legitimately, the attacker's pre-created account is activated instead, effectively hijacking their account.
- No prior access required.
- Triggers via forged external identity data.
- Leads to unauthenticated account takeover.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could pre-create an account bound to a victim's external identity provider, allowing a later genuine login to hijack the account. This could occur when the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback.
- User accounts could be taken over.
- Forged identity fields submitted to endpoint.
- Victim's account access is compromised.
Operational Fix
Recommended remediation, mitigation, and detection steps
The ZITADEL platform's authentication bypass vulnerability requires immediate attention from teams responsible for identity and access management. The first practical step is to identify all ZITADEL instances, confirm their exposure to the internet and business criticality, and then determine the accountable owner for remediation.
- Identify ZITADEL instance owners.
- Verify external reachability and criticality.
- Plan coordinated remediation efforts.