CVE-2026-56666 Details
Description
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler checks that the local user's email is verified but does not verify that the external IdP confirmed ownership of the same email before auto-linking by email, allowing a permissive provider account with a victim email address to be linked to the victim's local account. This issue is fixed in version 4.15.3.
A vulnerability exists in ZITADEL's external identity provider (IdP) handler, specifically in versions 4.0.0 through 4.15.2, prior to the patch in 4.15.3. The issue arises when auto-linking accounts by email, as the system only verifies the local user's email and not the external IdP's confirmation of ownership. This oversight can lead to unauthorized account linking, allowing an attacker to gain access to a victim's account by exploiting the email verification flaw.
Users can upgrade to ZITADEL version 4.15.3 or later, where this vulnerability has been fixed. If an immediate upgrade is not possible, auto-linking by email can be disabled or restricted to trusted enterprise identity providers that enforce email verification.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zitadel/zitadel/commit/c97012f0c5dc2fe960ae6e940cbea23229f0557f | [email protected] | Source CodeVendor |
| https://github.com/zitadel/zitadel/releases/tag/v4.15.3 | [email protected] | Release NotesVendor |
| https://github.com/zitadel/zitadel/security/advisories/GHSA-992q-9gwp-7r79 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ZITADEL | >= 4.0.0, <= 4.15.2 (semver) >= 3.0.0, <= 3.4.12 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion