External risk intelligence

ZITADEL Account Pre-Hijacking via Forged External Identity Callback

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105215

ZITADEL is an identity management and authentication platform designed to be internet-facing for handling user logins, identity federation, and registration services. The vulnerability exists within the Login UI and registration endpoints, which are public-facing by design to facilitate authentication for users and applications over the internet.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in ZITADEL's hosted Login UI, specifically affecting how external account registrations are handled. This flaw could allow unauthenticated attackers to bypass standard authentication processes by pre-creating accounts linked to a victim's external identity provider. Subsequent legitimate logins by the victim could then inadvertently associate their account with the attacker's pre-created entry.

  • Authentication bypass allows account pre-hijacking.
  • Affects public-facing login and registration processes.
  • Confirm relevance and potential exposure to understand impact.

Attack Path

How an attacker could exploit the issue

An attacker can bypass standard login procedures by exploiting a flaw in the hosted Login UI's registration endpoint. This allows them to pre-create an account linked to a victim's external identity provider. When the victim later attempts to log in legitimately, the attacker's pre-created account is activated instead, effectively hijacking their account.

  • No prior access required.
  • Triggers via forged external identity data.
  • Leads to unauthenticated account takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could pre-create an account bound to a victim's external identity provider, allowing a later genuine login to hijack the account. This could occur when the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback.

  • User accounts could be taken over.
  • Forged identity fields submitted to endpoint.
  • Victim's account access is compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

The ZITADEL platform's authentication bypass vulnerability requires immediate attention from teams responsible for identity and access management. The first practical step is to identify all ZITADEL instances, confirm their exposure to the internet and business criticality, and then determine the accountable owner for remediation.

  • Identify ZITADEL instance owners.
  • Verify external reachability and criticality.
  • Plan coordinated remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZITADEL?

ZITADEL is an identity management and access control platform. Organizations use it to handle user authentication, identity federation, and registration services for their applications. It is designed to manage the flow of users logging in via various providers, acting as a central hub that bridges user identities with the services they need to access.

What does CWE-290 mean for CVE-2026-105215?

CWE-290 refers to Authentication Bypass by Spoofing. In the context of this CVE, it means the application incorrectly trusts incoming data that claims to be from a legitimate identity provider. Because the system accepts these forged details without verifying them through a proper callback process, an attacker can trick the system into creating an account based on fake information.

How can an attacker trigger this vulnerability?

An attacker triggers this by submitting manipulated data, specifically forged identity provider and user identifiers, to the registration endpoint. The bug occurs because the endpoint accepts these client-supplied values without waiting for a legitimate identity provider to confirm the callback. Simply visiting the login page or using a standard, valid login does not trigger this issue.

Is my ZITADEL instance at risk?

Halo Surface Signal indicates that ZITADEL is typically configured to be internet-facing to support remote user authentication and federation. If your instance is accessible from the public internet, it is at higher risk because the affected Login UI registration endpoint is exposed to unauthenticated users globally. Internal instances not exposed to the public may have a more limited attack surface.

What should I do if I run ZITADEL?

Start by locating all ZITADEL instances in your environment and identifying the teams responsible for them. Prioritize these systems based on their business criticality and public accessibility. Once you have a clear inventory, work with those teams to verify if your current version is affected and initiate the patching process as instructed by the platform's official security guidance.

References