Authentication Flaw in ZITADEL's Hosted Login V1 UI
CVE-2026-105210

8.8HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105210?

ZITADEL versions prior to 3.4.15 and 4.17.1 contain a missing authentication flaw in the Login V1 UI. This issue allows attackers to exploit the second-factor enrollment and initialization handlers, which operate within an identity-only session prior to the verification of the primary factor. By solely possessing the victim's login name, attackers can register TOTP, OTP-SMS, OTP-Email, or U2F factors under their control, overwrite the verified phone number, and potentially enumerate users by exploiting discrepancies in error messages.

Affected Version(s)

zitadel 0 < 4.17.1

zitadel 0 < 3.4.15

zitadel 4.17.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

grvijayan
livio-a
lucasdodgson
AdamKorcz
.