Authentication Bypass Vulnerability in ZITADEL Products by ZITADEL
CVE-2026-105212
What is CVE-2026-105212?
The ZITADEL platform, specifically versions 3.x prior to 3.4.14 and 4.x prior to 4.16.2, is susceptible to an authentication bypass vulnerability. This flaw is present in the Login V1 and Login V2 user interfaces, allowing unauthorized attackers to enroll a passkey or other authenticator during identify-only login sessions without having to validate a primary authentication factor. As a result, attackers who possess only a victim's login name can register an authenticator under their control, granting them unauthorized access as if they were the legitimate user, effectively bypassing existing security measures such as traditional passwords and multi-factor authentication (MFA).
Affected Version(s)
zitadel 0 < 4.16.2
zitadel 0 < 3.4.14
zitadel 4.16.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
