ZITADEL’s 10-CVE Authentication Bypass Cluster Exposes the Self-Hosted IdP Trust Gap
A coordinated disclosure on October 4, 2026, exposed a critical authentication bypass cluster within the ZITADEL open-source identity provider. Spanning versions 3.x and 4.x, the vulnerability set includes seven critical-severity flaws, three high-severity issues, and one medium-severity vulnerability. These findings demonstrate a systemic failure in how identity state is managed, allowing unauthenticated actors to manipulate…