ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
ZITADEL, an open-source identity and access management platform, contains a critical authentication bypass vulnerability in its Login V1 UI that allows unauthenticated attackers to pre-create accounts bound to victims' external identity provider (IdP) identities. The vulnerability stems from the 'external account not found' registration endpoint trusting client-supplied external identity fields (IDPConfigID and ExternalUserID) without validating that a completed IdP callback has occurred. This means an attacker can forge these values to create an account that will later authenticate as the victim when the victim performs a legitimate external login. The vulnerability affects ZITADEL versions before 3.4.14 and 4.x before 4.16.2, with a CVSS score of 9.1 indicating critical severity. Organizations using ZITADEL for federated authentication are at direct risk of account takeover, as the attack requires no prior authentication and can compromise any user leveraging external IdP login methods.
While this CVE maps to CWE-290 (Authentication Using a Broken or Risky Cryptographic Algorithm) and currently has no direct MITRE ATT&CK technique mappings, the attack pattern aligns with credential-based compromise techniques that Casky practitioners would identify through behavioral analysis of authentication flows. Casky's Claude-powered reasoning engine would detect this vulnerability's attack chain by analyzing anomalous account creation patterns—specifically, accounts created without corresponding IdP callback logs, followed by successful external authentications from unexpected origins. Security teams using Casky would see findings highlighting the creation of ghost accounts tied to external identities, mismatches between account creation timestamps and IdP session initiation, and authentication successes that bypass normal federated login workflows. Practitioners should prioritize upgrading to patched versions and implementing additional validation requiring IdP callback completion before account binding, while monitoring authentication logs for the telltale pattern of pre-created accounts being activated by external logins.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-105215. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation