PULSE
FEED
ransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomsafepay reclama a halservice.it · IT · Professional Servicesransomsafepay reclama a grundens.com · US · Retail & E-Commerceransomsafepay reclama a t-systems.com · DE · Technologyransomqilin reclama a CORBY ROCK MILL · IE · Manufacturingransomqilin reclama a Delta Marine · FI · Transportationransomqilin reclama a J&D Financial · Financial Servicesransomendzone reclama a Philander Smith University · US · Educationransomsilentransomgroup reclama a A...n · Not Foundransomnetrunner reclama a M** A******* G********** O******* a** P***** S****** A********* · US · Not Foundransomqilin reclama a Global Security Concepts · US · Professional Servicesransombyod reclama a Standpointe / Trinite Solutions · Professional Servicesransomsafepay reclama a dd-automation.ch · CZ · Technologyransomsafepay reclama a stuecheli.ch · CH · Retail & E-Commerceransomsafepay reclama a bwi-bau.de · DE · Professional Servicesransomsafepay reclama a halservice.it · IT · Professional Servicesransomsafepay reclama a grundens.com · US · Retail & E-Commerceransomsafepay reclama a t-systems.com · DE · Technology
← Todos los CVEs
CVE Watch4 oct 2026

CVE-2026-105207

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a

CVSS

9.8

Crítico

EPSS

0.3%

p22

KEV

—

Exploit Today

7

0-100

Publicado: 4 oct 2026 · Última mod.: 4 oct 2026 · CWE-306

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-942939.8 CRÍ
—
———An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.7h
CVE-2026-1054867.3 ALT
—
———A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d96368b61f6e0c21df51df. The affected component should be upgraded.12h
CVE-2026-105786—
—
——0Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, packages/server/src/models/ApplicationModel.ts accepts a caller-chosen application authorization identifier, applications/:id/confirm binds that identifier to a logged-in user through a generic consent page, and the public packages/server/src/routes/api/application_auth.ts endpoint passes it to ApplicationModel.createAppPassword without authenticating or binding the redeemer. An attacker can cause a victim to approve the attacker's identifier, redeem a durable application ID and password, and exchange the credential for a victim session with full read and write access to synchronized data. This vulnerability is fixed in 3.7.13.14h
CVE-2026-712996.5 MED
—
——0A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS).18h
CVE-2026-712975.4 MED
—
——0A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.18h
CVE-2026-1053077.3 ALT
—
——0A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.22h