CVE-2026-105209 - ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment
CVE ID :CVE-2026-105209 Published : Oct. 4, 2026, 1:10 p.m. | 2 hours, 17 minutes ago Description :ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the...