PT-2026-104636 · Zitadel · Zitadel
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 3.x through 3.4.13
ZITADEL versions 4.x through 4.16.1
Description
An authentication bypass exists in the hosted Login V1 and Login V2 UIs. The system allows the enrollment of a passkey or other authenticator during identify-only login sessions before a primary factor is verified. An unauthenticated attacker who knows a victim's login name can register an attacker-controlled authenticator to gain unauthorized access to the account, bypassing passwords and multi-factor authentication (MFA).
Recommendations
Update ZITADEL 3.x to version 3.4.14 or later.
Update ZITADEL 4.x to version 4.16.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel