Vulnerability Exposing Trust Gaps in Self-Hosted Identity Providers: 10 CVE Authentication Bypasses of ZITADEL
2026-10-05 19:50:22
According to CoinMeta, on October 4, 2026, ZITADEL disclosed a critical set of authentication bypass vulnerabilities involving their open-source identity providers, covering versions 3.x and 4.x. The vulnerabilities included 7 severe flaws, 3 high-risk issues, and 1 medium-risk issue. These findings revealed a systemic failure in identity status management that allowed unauthenticated actors to manipulate the authentication process before primary factor verification. The technical core of these vulnerabilities lies in an architectural defect in the ZITADEL codebase; the stream processor relied solely on login names to bind accounts without verifying any authentication factors, resulting in the failure of key security controls. The severity of these vulnerabilities highlights the extent of the exposure, including CVE-2026-105209 (CVSS 9.6), which permitted cross-organizational key registration. Attackers could obtain registration codes for users from different organizations within the same instance, enabling them to take complete control of the accounts.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.