CVE-2026-105208 HIGH

CVE-2026-105208: ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens

Vendor Zitadel
Product zitadel
Weakness CWE-649
Published October 4, 2026
Last update October 5, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.

Key dates

02Disclosure timeline

October 4, 2026 CVE published
October 5, 2026 Record updated