MEDIUM 4.8 GitHub
CVE-2026-56666
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
### Summary
A flaw in the external identity provider handler allows unauthorized account linking to occur under specific administrative configurations. When auto-linking by email is enabled, ZITADEL checks that the local user's email is verified, but does not explicitly cross-check whether the incoming external identity provider (IdP) also verified that email address upstream.
### Impact
When a user logs in via an external identity provider, the system can automatically link them to an existi
Affected Products
- go/github.com/zitadel/zitadel < 4.15.3
References
- https://github.com/advisories/GHSA-992q-9gwp-7r79
- https://github.com/zitadel/zitadel/security/advisories/GHSA-992q-9gwp-7r79
- https://nvd.nist.gov/vuln/detail/CVE-2026-56666
- https://github.com/zitadel/zitadel/commit/c97012f0c5dc2fe960ae6e940cbea23229f0557f
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-09-11 via GitHub. Affected: go/github.com/zitadel/zitadel < 4.15.3.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.