Dev.to Security 🔐 Cybersecurity 👁 0

ZITADEL Cluster: 7 CVEs, Peak CVSS 9.3 — Cross-Org Account Takeover via Passkey Enrollment

An attacker with minimal write permissions in one ZITADEL organization can take over accounts in another. CVE-2026-105209 (CVSS 9.3) lets them forge the x-zitadel-orgid header to issue passkey enrollment codes for users

An attacker with minimal write permissions in one ZITADEL organization can take over accounts in another. CVE-2026-105209 (CVSS 9.3) lets them forge the x-zitadel-orgid header to issue passkey enrollment codes for users in any other org — then register their own authenticator.

Two more critical paths in the same cluster:

CVE-2026-105215 (9.1) — account pre-hijacking via forged IdP callback fields (no auth required)
CVE-2026-105211 (8.1) — OTP codes leaked in Login V2 server-action responses, MFA bypassed
CVE-2026-105210 (8.8) — 2FA enrollment bypass in Login V1
CVE-2026-105208 (7.7) — session hijacking via malleable IdP intent token encryption

Fix: upgrade to 4.17.3 (4.x) or 3.4.15 (3.x). Then audit cross-org passkey enrollments and rotate admin credentials.

Full breakdown: https://threataft.com/articles/zitadel-cluster-cve-2026-105209-105215-105211-105208-105206-105210-105213

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.