MEDIUM 4.8 GitHub

CVE-2026-56666

ZITADEL: Auto-linking by email: IdP-side email verification is not checked

### Summary A flaw in the external identity provider handler allows unauthorized account linking to occur under specific administrative configurations. When auto-linking by email is enabled, ZITADEL checks that the local user's email is verified, but does not explicitly cross-check whether the incoming external identity provider (IdP) also verified that email address upstream. ### Impact When a user logs in via an external identity provider, the system can automatically link them to an existi

Affected Products

References

Published: 2026-09-11 · Source: GitHub · Feed updated: 2026-09-11
This medium severity vulnerability with a CVSS score of 4.8 was published on 2026-09-11 via GitHub. Affected: go/github.com/zitadel/zitadel < 4.15.3.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.