search
Zitadel
Trends
- 1ZITADEL hit by seven vulnerabilities enabling account takeover●ZITADEL cluster — 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header → issue passkey enrollment for any
Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.