Authentication Bypass Vulnerability in ZITADEL by ZITADEL
CVE-2026-105211
9.2CRITICAL
What is CVE-2026-105211?
ZITADEL versions before 4.17.1 are vulnerable to an authentication bypass affecting the Login V2 feature. This issue allows attackers to exploit the OTP returnCode delivery method, enabling them to obtain one-time passwords sent to users via email or SMS. By knowing the login name of a targeted user, attackers can gain access to MFA-authenticated sessions, potentially resulting in unauthorized account takeovers, including administrator accounts. Proper security measures and updates should be implemented to mitigate this vulnerability.
Affected Version(s)
zitadel 0 < 4.17.1
zitadel 4.17.1
