Authentication Bypass in ZITADEL 4.x by Deactivated Organizations
CVE-2026-105213
8.8HIGH
What is CVE-2026-105213?
ZITADEL version 4.x prior to 4.17.1 is vulnerable to an authentication bypass issue wherein it fails to check the inactive state of an organization during the Login V2 authentication process. This flaw allows users belonging to a deactivated organization, who possess valid credentials or existing sessions, to still authenticate successfully, create new sessions, and obtain or refresh authentication tokens without appropriate checks, potentially compromising organizational security.
Affected Version(s)
zitadel 0 < 4.17.1
zitadel 4.17.1
