CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105215

CRITICALCVSS 9.1NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConf

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105215 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105215

CRITICALCVSS 9.1NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConf

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]