A login name is all it takes. ZITADEL 3.x gets no fix.
By Lior AharonovFounder, 7IT Solutions ·
On Sunday, 4 October, CVE-2026-105207 (CVSS 9.8) was published for ZITADEL, the open source identity platform. Versions 3.0.0 through 3.4.15 and 4.0.0 through 4.17.2 let an unauthenticated attacker who knows a victim's login name link their own external identity provider to that account, then sign in as the victim. The fix is 4.17.3.
If ZITADEL runs your customer login, a known username can turn into someone else's session: a stranger opening your customer's dashboard with a social login that was never theirs. And the 3.x line reached end of life on 31 August, so it will not get a patch.
If you self-host ZITADEL, check the version today and upgrade to 4.17.3 or later. Still on 3.x, move to 4.x now; disabling external IdP linking only closes part of the gap, says ZITADEL.
End of life is a date on someone else's calendar. Attackers read that calendar too.
Lior Aharonov · my takeSources
- ZITADEL security advisory GHSA-g8gj-gq47-xgf4 github.com
- NVD: CVE-2026-105207 nvd.nist.gov
Researched with AI tools; every fact is checked against the linked sources.