ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 3.0.0 through 3.4.15 and 4.x before 4.17.3 contains an incorrect authorization flaw in the User Service API, which verifies user.read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered. | |
| Title | ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:01.420Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105206
No data.
Status : Deferred
Published: 2026-10-04T15:16:31.517
Modified: 2026-10-04T15:16:31.627
Link: CVE-2026-105206
No data.
OpenCVE Enrichment
Updated: 2026-10-04T19:30:05Z
Weaknesses