CVEs classified under CWE-649, newest first.
1 CVERSS
CVE-2026-105208
ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login inten…