MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #8

ZITADEL hit by seven vulnerabilities enabling account takeover

Original: ZITADEL cluster — 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header → issue passkey enrollment for any

Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.

Why now: The severity of the flaws and the risk of full account takeover across tenants make this urgent reading for anyone running identity infrastructure.

ZITADEL

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1079459