CVE-2026-105209 | Zitadel up to 3.4.14/4.17.0 Enrollment x-zitadel-orgid improper authorization (EUVD-2026-92102)

SecurityVulns

A vulnerability, which was classified as critical, was found in Zitadel up to 3.4.14/4.17.0. Affected by this issue is some unknown functionality of the component Enrollment. The manipulation of the argument x-zitadel-orgid results in improper authorization.

This vulnerability is identified as CVE-2026-105209. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More