ZITADEL's hosted Login V1 UI had an authentication bypass that lets an unauthenticated attacker reserve someone else's external login. The vendor patched it in 4.16.2 and 3.4.14. The public record is CVE-2026-105215, scored 9.1 on CVSS 3.1 and 9.3 on CVSS 4.0.
What happened
The "external account not found" registration endpoint trusted IDPConfigID and ExternalUserID values sent by the client, without a completed identity-provider callback. An attacker who can reach a Login V1 flow can submit forged fields and create an account bound to a victim's external identity, such as a known GitHub user id, when that IdP allows manual account creation.
The victim's later genuine "Sign in with ..." then lands in the pre-created account. Login V2 is not on this path. It uses a cryptographically bound IdP intent. Automatic account creation, which runs only after a verified callback, is also not the vulnerable path. The bug was reported by Michael Wollner of Deutsche Telekom and by Adam Korczynski of Ada Logics, the latter with help from Anthropic. It was published on 4 October 2026. It is not in CISA's exploited catalog.
Who is affected
- ZITADEL 4.0.0 through 4.16.1, and 3.x through 3.4.13, when users authenticate through hosted Login V1.
- Deployments with at least one external IdP that allows manual account creation. That setting is what opens the registration path.
- Applications hanging off that login: SSO into internal tools, customer portals, and partner access. Login V2-only setups are outside this issue.
What to do now
Upgrade to 4.16.2 or 3.4.14. If you cannot upgrade today, turn off "Account creation allowed (manually)" on each external IdP. That closes the vulnerable path and also blocks legitimate self-service signup through that IdP, so warn the service desk first. After patching, look for external-login accounts created before the user's first real IdP callback.
Source: ZITADEL security advisory GHSA-738m-7888-jfv8. Unauthenticated account pre-hijacking via forged external identity provider callback in Login V1. Record: CVE-2026-105215.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-61500: Rejetto HFS admin session forgery, CVSS 9.3
- Google OSS VRP paused 1 October after AI bug-report flood
- CVE-2026-102489: Zammad session flaw chained to root, due 5 October
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.