7IT · News

A login name is all it takes. ZITADEL 3.x gets no fix.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Sunday, 4 October, CVE-2026-105207 (CVSS 9.8) was published for ZITADEL, the open source identity platform. Versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 let an unauthenticated attacker who knows a victim's login name link their own external identity provider to that account, then sign in as the victim. The fix is 4.17.3.

Why it matters

If ZITADEL runs your customer login, a known username can turn into someone else's session: a stranger opening your customer's dashboard with a social login that was never theirs. And the 3.x line reached end of life on 31 August, so it will not get a patch.

What to do

If you self-host ZITADEL, check the version today and upgrade to 4.17.3 or later. Still on 3.x, move to 4.x now; disabling external IdP linking only closes part of the gap, says ZITADEL.

End of life is a date on someone else's calendar. Attackers read that calendar too.

Lior Aharonov · my take

Sources

securityidentityauthenticationopen-sourcecve

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.