PT-2026-104637 · Zitadel · Zitadel

·

CVE-2026-105213

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.x through 4.17.0
Description Login V2 authentication fails to verify the inactive state of an organization, checking only the status of the individual user. This allows users belonging to a deactivated organization to sign in, create sessions, and obtain or refresh tokens if they possess valid credentials, an existing session, or a refresh token.
Recommendations Update ZITADEL to version 4.17.1.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105213
GHSA-558C-V5WC-9W4Q

Affected Products

Zitadel