PT-2026-98200 · Zitadel · Zitadel
CVE-2026-85056
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ZITADEL versions 4.0.0 through 4.16.0
Description
ZITADEL Login V2 creates a browser session immediately after password verification. This session can be reused for subsequent authentication requests without verifying a user's enrolled second factor, such as TOTP (Time-based One-Time Password), OTP (One-Time Password), or U2F (Universal 2nd Factor). If the MFA step is abandoned and the login process is restarted, the system may reuse the existing session to complete an OIDC (OpenID Connect) or SAML (Security Assertion Markup Language) callback for customer applications. This occurs when the organization has not enabled Force MFA or Force MFA for local users only, allowing voluntarily enrolled factors to be skipped. This issue specifically affects customer applications using the Login V2 UI and does not impact Login V1, the ZITADEL Console, Management and Admin APIs, or user self-management.
Recommendations
Upgrade ZITADEL to version 4.16.1 or later.
As a temporary workaround, enable Force MFA or Force MFA for local users only in the affected organization's or instance default login policy to make second-factor verification mandatory.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel