rootpwn

critical · CVSS v3 9.6 · CVSS v4 9.3

CVE-2026-105209

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey o…

Description

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.

Scores

Severity
critical
CVSS v2
8.5
CVSS v3
9.6
CVSS v4
9.3
EPSS
—

← All CVEs