Authentication Bypass in ZITADEL 4.x by Deactivated Organizations
CVE-2026-105213

8.8HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105213?

ZITADEL version 4.x prior to 4.17.1 is vulnerable to an authentication bypass issue wherein it fails to check the inactive state of an organization during the Login V2 authentication process. This flaw allows users belonging to a deactivated organization, who possess valid credentials or existing sessions, to still authenticate successfully, create new sessions, and obtain or refresh authentication tokens without appropriate checks, potentially compromising organizational security.

Affected Version(s)

zitadel 0 < 4.17.1

zitadel 4.17.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

livio-a
.