HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105211 — ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V...

·Source: NIST NVD

Updated:

Executive Summary

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

Analysis

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover. CVSS Score: 8.1. Published: 2026-10-04T15:16:32.333.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105211
Source Attribution

Originally published by NIST NVD on Oct 4, 2026. Verified by: NIST.

Related Threats