Authentication Flaw in ZITADEL's Hosted Login V1 UI
CVE-2026-105210
8.8HIGH
What is CVE-2026-105210?
ZITADEL versions prior to 3.4.15 and 4.17.1 contain a missing authentication flaw in the Login V1 UI. This issue allows attackers to exploit the second-factor enrollment and initialization handlers, which operate within an identity-only session prior to the verification of the primary factor. By solely possessing the victim's login name, attackers can register TOTP, OTP-SMS, OTP-Email, or U2F factors under their control, overwrite the verified phone number, and potentially enumerate users by exploiting discrepancies in error messages.
Affected Version(s)
zitadel 0 < 4.17.1
zitadel 0 < 3.4.15
zitadel 4.17.1
