Open Source Identity Management Platform Vulnerability in ZITADEL
CVE-2026-85056
8.2HIGH
What is CVE-2026-85056?
The ZITADEL platform, an open-source identity management tool, has a vulnerability that allows an attacker to reuse an existing browser session after the password has been verified. This flaw primarily affects versions 4.0.0 to 4.16.1 and enables the bypassing of Multi-Factor Authentication (MFA) steps under certain configurations, potentially exposing user accounts to unauthorized access. The vulnerability arises because session validity checks may not require MFA when the organization has not enforced it strictly. The issue has been addressed in version 4.16.1.
Affected Version(s)
zitadel >= 4.0.0, < 4.16.1
