CVE-2026-105207 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-105207 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-105207 is a critical authentication-bypass issue in ZITADEL affecting versions 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3. The flaw lets an attacker link their own external identity provider account to a victim’s ZITADEL account without proving they are the account owner or having permission to do so. In practice, if an attacker knows a victim’s login name, they may be able to sign in as that victim.

This is especially urgent for solo developers and small teams because identity systems often sit at the center of admin access, customer auth, and internal tooling. Even without known active exploitation, the impact is account takeover with full trust-chain consequences.

Immediate Action

  • Patch now to 4.17.3 or later if you run ZITADEL 4.x; if you are on 3.x, plan an immediate upgrade path to a fixed release or vendor-supported migration target. See the vendor advisory: TODO: ZITADEL security advisory.
  • Disable or restrict external identity linking until patched, especially any self-service account linking and any “login without primary factor” flows.
  • Review recent account-link events and investigate any unexpected IdP associations, especially for admin, billing, and support accounts.
  • Rotate credentials and session tokens for high-value accounts if you suspect exposure. Revoke active sessions where possible.
  • Temporarily isolate the auth service from public exposure if you cannot patch immediately; place it behind VPN/IP allowlists or maintenance mode.
  • Back up current config and database before upgrading, so you can roll back cleanly if the deployment fails.

Affected Versions

  • zitadel@3.0.0 through 3.4.15 vulnerable; upgrade to a vendor-fixed 3.x release if available, or migrate to 4.17.3+.
  • zitadel@4.0.0 through 4.17.2 vulnerable; upgrade to 4.17.3 or later.
  • zitadel@4.17.3 and later: fixed.

Resolution Guide

Docker / container deployments

docker pull zitadel/zitadel:4.17.3
docker stop zitadel
docker rm zitadel
docker run -d --name zitadel \
  -p 8080:8080 \
  -e ZITADEL_LOG_LEVEL=info \
  zitadel/zitadel:4.17.3

Docker Compose

services:
  zitadel:
    image: zitadel/zitadel:4.17.3
    restart: unless-stopped

Linux package managers (if your distro packages ZITADEL; otherwise use the container upgrade path)

# Debian/Ubuntu
sudo apt update
sudo apt install --only-upgrade zitadel

# RHEL/CentOS/Fedora
sudo yum update zitadel
# or
sudo dnf update zitadel

JavaScript / Python / Java: ZITADEL is typically deployed as a service, not a library. If you vendor it into a platform package, update the service image or package reference directly:

# npm/yarn/pnpm: update the deployment package or Helm chart, not a runtime library
npm i -D TODO:your-zitadel-deployment-package@latest
yarn add -D TODO:your-zitadel-deployment-package@latest
pnpm add -D TODO:your-zitadel-deployment-package@latest

# pip/pipx: same note; update the wrapper or deployment tooling
pip install -U TODO:your-zitadel-deployment-package
pipx upgrade TODO:your-zitadel-deployment-package

# Maven/Gradle: update the container/image tag or platform BOM
mvn -DskipTests package
./gradlew build

Hardening until patched

# Example feature-flag style hardening (adjust to your deployment)
ZITADEL_DISABLE_IDP_LINKING=true
ZITADEL_ALLOW_SELF_SERVICE_LINKING=false
ZITADEL_REQUIRE_PRIMARY_FACTOR_FOR_LINKING=true

Minimal code/config guard if you have a reverse proxy or auth gateway in front of ZITADEL:

# Block direct access to account-link endpoints until fixed
location ~* /.*(AddIDPLink|idp/link|login/v2).* {
  deny all;
}

Detection & Verification

Check your version first. If you run a container:

docker image inspect zitadel/zitadel:latest --format '{{.RepoTags}}'
docker ps --format 'table {{.Names}}\t{{.Image}}\t{{.Status}}'

If ZITADEL is installed as a service, inspect the binary or package metadata:

zitadel version
dpkg -l | grep -i zitadel
rpm -qa | grep -i zitadel

Search configs and logs for identity-linking activity and suspicious account associations:

grep -RniE 'AddIDPLink|idp link|external identity|Login V2|link' /etc/zitadel /var/log 2>/dev/null

Verify the fix by confirming the running version is 4.17.3 or later and by testing that linking requires proper authentication/authorization:

curl -s http://localhost:8080/healthz
curl -s http://localhost:8080/ | head
# Confirm admin console / API reports the patched version

If you use dependency or image scanners, rerun them after the upgrade:

trivy image zitadel/zitadel:4.17.3
grype zitadel/zitadel:4.17.3

Risk and Impact

This bug can let an attacker take over a victim’s account simply by knowing the victim’s login name and linking the attacker’s external identity to that account. Once linked, the attacker can authenticate as the victim and inherit whatever permissions the victim has, including admin access.

For small teams, the blast radius can be broad: customer data exposure, privilege escalation, CI/CD compromise, and persistence through trusted identity links. Treat this as a full account-takeover event, not a minor login bug.

Keep reading