ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent. An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
ZITADEL, a widely-deployed open-source identity platform, uses weak encryption to protect IdP intent tokens in versions 4.x before 4.17.3 and 3.x through 3.4.15. The vulnerability allows authenticated attackers to manipulate their own tokens and replay them for another user's external login flow. By predicting victim intent identifiers and winning a timing race condition, an attacker can steal IdP tokens or hijack sessions entirely—a critical flaw in authentication infrastructure that affects any organization relying on ZITADEL for identity management across federated systems.
While this CVE currently shows zero matching Casky skills due to its specificity to ZITADEL's cryptographic implementation, practitioners using Claude AI with extended reasoning would detect the underlying attack patterns through behavioral anomalies. The assault combines techniques aligned with credential theft, session hijacking, and race condition exploitation. Detection would surface as: (1) unusual token reuse across different user contexts in IdP intent logs, (2) rapid sequential calls to /v2/idp_intents or /v2/sessions endpoints from single authenticated users, (3) timing correlations between token generation and validation requests, and (4) cross-user session establishment without corresponding authentication events. Organizations should immediately patch to 4.17.3 or later and monitor authentication logs for evidence of token manipulation attempts.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-105208. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation