CRITICAL 9.3 NVD
CVE-2026-105209
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it chec
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-pq2q-2c6r-75c4
- https://www.vulncheck.com/advisories/zitadel-before-3.4.15-and-4.17.1-cross-organization-a
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-04 via NVD.
Risk Timeline
CVE Disclosed2026-10-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 10549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.