CVE-2026-105215

CVE-2026-105215 published: ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthen...

View full NVD advisory → ← Back to CVE watch