PT-2026-104635 · Zitadel · Zitadel

·

CVE-2026-105211

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions prior to 4.17.1
Description An authentication bypass exists in Login V2 that allows unauthenticated attackers to take over accounts. Attackers who know the login name of a victim enrolled in OTP-Email and OTP-SMS can obtain One-Time Password (OTP) codes through the returnCode delivery type by reading them from server-action responses. This allows the attacker to establish MFA-authenticated sessions, which may include the takeover of administrator accounts.
Recommendations Update ZITADEL to version 4.17.1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105211
GHSA-3GWM-5WX8-4GM6

Affected Products

Zitadel