Overview / Introduction
The open-source identity provider ZITADEL has become the subject of a sweeping security incident that threatens every self-hosted deployment. On October 4, 2026, a coordinated disclosure revealed a cluster of ten CVEs that collectively undermine the fundamental trust model of ZITADEL’s authentication flow. The flaws span from unauthenticated authentication-bypass to MFA/OTP bypass and even cross-organization passkey enrollment. The result is a scenario where an attacker can pre-hijack accounts, register their own authenticators for users in other orgs, and traverse the entire IdP instance without ever completing a primary factor verification.
Technical Details
The root cause is an architectural oversight: flow handlers in ZITADEL’s codebase were found to act on accounts identified solely by a login name before any authentication factor was verified. This means that an unauthenticated session could trigger stateful operations that should have been gated by a fully authenticated context.
- CVE-2026-105209 (CVSS 9.6) - Cross-organization passkey enrollment. An attacker with user-write permissions in Org A can retrieve an enrollment code for a user in Org B on the same instance, register a personal authenticator, and gain full account takeover.
- CVE-2026-105215 (CVSS 9.1) - Unauthenticated account pre-hijacking in the Login V1 UI. The system accepts client-supplied external identity fields before completing an identity-provider callback, allowing hijacking of accounts that have never logged in.
- CVE-2026-105214 (CVSS 9.1) - Server-side request forgery via organization domain HTTP verification. Attackers can trigger internal network scans or access cloud metadata by manipulating the domain verification process.
- CVE-2026-105211 (CVSS 9.1) - MFA and OTP bypass in Login V2. The MFA challenge is not tied to a verified session, permitting bypass of the second factor.
- CVE-2026-105207 (CVSS 9.1) - Unauthenticated identity binding. Attackers can bind their own identity to a victim’s account before the primary factor is verified.
- CVE-2026-105212 (CVSS 8.5) - Acceptance of enrollment actions on identify-only sessions.
- CVE-2026-105210 (CVSS 8.5) - Same issue as above, but for authentication actions.
- CVE-2026-105213 (CVSS 8.0) - Users of deactivated organizations retain access.
- CVE-2026-105208 (CVSS 8.0) - Exposure of identity provider intent tokens to manipulation.
- CVE-2026-105206 (CVSS 6.5) - Cross-organization user enumeration.
# Example of a malicious payload exploiting CVE-2026-105209
POST /api/v2/passkey/enroll HTTP/1.1
Host: idp.example.com
Content-Type: application/json
{ "target_user": "[email protected]", "org_id": "org-a-123", "enrollment_code": "malicious-code"
}
Impact Analysis
Any organization running a self-hosted ZITADEL instance on the 3.x branch is permanently exposed, as that line reached end-of-life on August 31, 2026 and will receive no further patches. Even the latest 4.x releases are affected, meaning all current deployments face the same authentication-bypass risk until a mitigation is applied. The severity is such that:
- Unauthenticated actors can hijack accounts before MFA or OTP is required.
- Attackers can enroll their own passkeys for users in other organizations, effectively stealing those accounts.
- Internal network reconnaissance becomes trivial via SSRF vectors.
- Lateral movement across multiple orgs in a single IdP instance is possible, turning a single compromised account into a full-blown privilege escalation platform.
Timeline of Events
- August 31, 2026 - 3.x branch reaches end-of-life.
- October 4, 2026 - Coordinated disclosure of the 10-CVE cluster by Forkast.
- October 5-6, 2026 - ZITADEL releases advisory and patches for 4.x.
- Immediate patching or migration to 4.x recommended.
Mitigation / Recommendations
- Patch immediately: Apply the latest 4.x release that contains the security fixes for all ten CVEs. If you are on 3.x, migrate to 4.x as soon as possible.
- Validate flow handlers: Ensure that all authentication flows verify a fully authenticated session before performing any state-changing operation.
- Enforce strict MFA post-authentication: Update your policy to require MFA after the primary factor, regardless of session state.
- Audit cross-org permissions: Review user-write permissions across organizations to prevent cross-org passkey enrollment abuse.
- Monitor for SSRF activity: Deploy WAF rules to detect and block suspicious domain verification requests.
- Implement zero-trust network segmentation: Isolate IdP components from internal networks to mitigate internal reconnaissance vectors.
Real-World Impact
Large enterprises that rely on ZITADEL for SSO across hundreds of internal applications could experience a single compromised user account turning into a gateway to all of their services. In multi-tenant SaaS scenarios, a malicious actor could register a passkey for a customer’s account, gaining access to sensitive data and potentially triggering a cascading breach. The SSRF vectors could allow attackers to read cloud provider metadata and exfiltrate secrets that are otherwise protected by IAM policies.
Expert Opinion
From a cybersecurity perspective, this incident underscores a fundamental flaw in how open-source IdPs handle authentication state. The assumption that a login name alone is sufficient to identify an account during flow handling is a classic example of a trust-but-verify failure. The breadth of the CVE cluster-affecting pre-factor, factor, and post-factor stages-suggests that the underlying architecture was designed with convenience over security, a mistake that has paid off for attackers.
For the industry, the lesson is clear: identity providers must enforce a strict, sequential authentication model. Any operation that modifies state or grants access must be gated by a fully authenticated and authorized session. The ZITADEL case also highlights the risks of end-of-life software in critical security infrastructure; even if a product is open source, lack of maintenance can leave customers in a permanent “vulnerable” state. Finally, the ability to perform cross-organization passkey enrollment points to the need for tighter isolation between tenants in multi-org IdPs.
In sum, the ZITADEL 10-CVE cluster is not just a patch-work of individual bugs; it is a systemic breakdown of the IdP’s trust model that could enable attackers to hijack, impersonate, and move laterally across an entire organization’s digital footprint. Immediate action is required to protect the integrity of identity services and the data they secure.