CVE-2026-105208 - ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
CVE ID :CVE-2026-105208 Published : Oct. 4, 2026, 3:16 p.m. | 2 hours, 11 minutes ago Description :ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is...