Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
ZITADEL versions 3.0.0 – 3.4.15 & 4.0.0<4.17.3 hit by CRITICAL vuln (CVE-2026-105207) — attackers can hijack accounts via IdP link. Patch status unclear: monitor advisories. 🚨 https://radar.offseq.com/threat/zitadel-300-through-3415-and-400-before-4173-creates-links-between-user-accounts-and-exte...
https://radar.offseq.com/threat/zitadel-300-through-3415-and-400-before-4173-creates-links-between-user-accounts-and-external-identity-cb61bb81cf2dabad
2026-10-05T04:30:28.059Z