PT-2026-98200 · Zitadel · Zitadel

CVE-2026-85056

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZITADEL versions 4.0.0 through 4.16.0
Description ZITADEL Login V2 creates a browser session immediately after password verification. This session can be reused for subsequent authentication requests without verifying a user's enrolled second factor, such as TOTP (Time-based One-Time Password), OTP (One-Time Password), or U2F (Universal 2nd Factor). If the MFA step is abandoned and the login process is restarted, the system may reuse the existing session to complete an OIDC (OpenID Connect) or SAML (Security Assertion Markup Language) callback for customer applications. This occurs when the organization has not enabled Force MFA or Force MFA for local users only, allowing voluntarily enrolled factors to be skipped. This issue specifically affects customer applications using the Login V2 UI and does not impact Login V1, the ZITADEL Console, Management and Admin APIs, or user self-management.
Recommendations Upgrade ZITADEL to version 4.16.1 or later. As a temporary workaround, enable Force MFA or Force MFA for local users only in the affected organization's or instance default login policy to make second-factor verification mandatory.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85056
GHSA-9993-RFWP-RHWF

Affected Products

Zitadel