PT-2026-104636 · Zitadel · Zitadel

·

CVE-2026-105212

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 3.x through 3.4.13 ZITADEL versions 4.x through 4.16.1
Description An authentication bypass exists in the hosted Login V1 and Login V2 UIs. The system allows the enrollment of a passkey or other authenticator during identify-only login sessions before a primary factor is verified. An unauthenticated attacker who knows a victim's login name can register an attacker-controlled authenticator to gain unauthorized access to the account, bypassing passwords and multi-factor authentication (MFA).
Recommendations Update ZITADEL 3.x to version 3.4.14 or later. Update ZITADEL 4.x to version 4.16.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105212
GHSA-45F2-5Q3R-XGG6

Affected Products

Zitadel