Vulnerability Exposing Trust Gaps in Self-Hosted Identity Providers: 10 CVE Authentication Bypasses of ZITADEL
2026-10-05 19:50:22
According to CoinMeta, on October 4, 2026, ZITADEL disclosed a critical set of authentication bypass vulnerabilities involving their open-source identity providers, covering versions 3.x and 4.x. The vulnerabilities included 7 severe flaws, 3 high-risk issues, and 1 medium-risk issue. These findings revealed a systemic failure in identity status management that allowed unauthenticated actors to manipulate the authentication process before primary factor verification. The technical core of these vulnerabilities lies in an architectural defect in the ZITADEL codebase; the stream processor relied solely on login names to bind accounts without verifying any authentication factors, resulting in the failure of key security controls. The severity of these vulnerabilities highlights the extent of the exposure, including CVE-2026-105209 (CVSS 9.6), which permitted cross-organizational key registration. Attackers could obtain registration codes for users from different organizations within the same instance, enabling them to take complete control of the accounts.
Source:Forkast
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

Bitcoin October 2026 Outlook: Can the 19% Historical Gain Hold?
09-30 12:57

Dogecoin Price: Whales Buy $112M, Can DOGE Break $0.10?
09-29 12:48

What is Solidigm? Is Its $150B IPO Valuation a Bubble?
09-28 13:00

Is PAXG Stable? Is Gold-Backed Better Than Stablecoins?
09-24 18:04

ETH Rebounds to $2,800: Can It Hold $3,200 by Month-End?
09-23 11:07



