Authentication Bypass Vulnerability in ZITADEL Products by ZITADEL
CVE-2026-105212

8.7HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105212?

The ZITADEL platform, specifically versions 3.x prior to 3.4.14 and 4.x prior to 4.16.2, is susceptible to an authentication bypass vulnerability. This flaw is present in the Login V1 and Login V2 user interfaces, allowing unauthorized attackers to enroll a passkey or other authenticator during identify-only login sessions without having to validate a primary authentication factor. As a result, attackers who possess only a victim's login name can register an authenticator under their control, granting them unauthorized access as if they were the legitimate user, effectively bypassing existing security measures such as traditional passwords and multi-factor authentication (MFA).

Affected Version(s)

zitadel 0 < 4.16.2

zitadel 0 < 3.4.14

zitadel 4.16.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ibonok
IAM-marco
lucasdodgson
livio-a
dkonis
FerasTr
pelegw
AdamKorcz
.