Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #8
ZITADEL hit by seven vulnerabilities enabling account takeover
Original: ZITADEL cluster — 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header → issue passkey enrollment for any
Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.
Why now: The severity of the flaws and the risk of full account takeover across tenants make this urgent reading for anyone running identity infrastructure.
Evidence
- ZITADEL cluster — 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header → issue passkey enrollment for any user in any org → full account takeover across tenants CVE-2026-105215 (9.1): pre-hijack accounts via forged IdP callback CVE-2026-105211 (8.1): OTP codes in… · threataft@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1079459