CRITICAL 9.3 NVD

CVE-2026-105209

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it chec

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.

References

Published: 2026-10-04 · Source: NVD · Feed updated: 2026-10-04
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-04 via NVD.

Risk Timeline

CVE Disclosed2026-10-04 · -1 days ago

Remediation Resources

vulnfeed aggregates 10549 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.