CVE-2026-105215: ZITADEL Login V1 account pre-hijack, CVSS 9.1
ZITADEL external IdP registration trusts forged identity fields

CVE-2026-105215: ZITADEL Login V1 account pre-hijack, CVSS 9.1

ZITADEL's hosted Login V1 UI had an authentication bypass that lets an unauthenticated attacker reserve someone else's external login. The vendor patched it in 4.16.2 and 3.4.14. The public record is CVE-2026-105215, scored 9.1 on CVSS 3.1 and 9.3 on CVSS 4.0.

What happened

The "external account not found" registration endpoint trusted IDPConfigID and ExternalUserID values sent by the client, without a completed identity-provider callback. An attacker who can reach a Login V1 flow can submit forged fields and create an account bound to a victim's external identity, such as a known GitHub user id, when that IdP allows manual account creation.

The victim's later genuine "Sign in with ..." then lands in the pre-created account. Login V2 is not on this path. It uses a cryptographically bound IdP intent. Automatic account creation, which runs only after a verified callback, is also not the vulnerable path. The bug was reported by Michael Wollner of Deutsche Telekom and by Adam Korczynski of Ada Logics, the latter with help from Anthropic. It was published on 4 October 2026. It is not in CISA's exploited catalog.

Who is affected

  • ZITADEL 4.0.0 through 4.16.1, and 3.x through 3.4.13, when users authenticate through hosted Login V1.
  • Deployments with at least one external IdP that allows manual account creation. That setting is what opens the registration path.
  • Applications hanging off that login: SSO into internal tools, customer portals, and partner access. Login V2-only setups are outside this issue.

What to do now

Upgrade to 4.16.2 or 3.4.14. If you cannot upgrade today, turn off "Account creation allowed (manually)" on each external IdP. That closes the vulnerable path and also blocks legitimate self-service signup through that IdP, so warn the service desk first. After patching, look for external-login accounts created before the user's first real IdP callback.

Source: ZITADEL security advisory GHSA-738m-7888-jfv8. Unauthenticated account pre-hijacking via forged external identity provider callback in Login V1. Record: CVE-2026-105215.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-102489: Zammad session flaw chained to root, due 5 October
Zammad helpdesk session fixation and local root escalation