CVE-2026-105207 - ZITADEL before 4.17.3 Account Takeover via External IdP Linking
CVE ID :CVE-2026-105207 Published : Oct. 4, 2026, 1:10 p.m. | 2 hours, 17 minutes ago Description :ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including...