Open Source Identity Management Platform Vulnerability in ZITADEL
CVE-2026-85056

8.2HIGH

Key Information:

Vendor

Zitadel

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-85056?

The ZITADEL platform, an open-source identity management tool, has a vulnerability that allows an attacker to reuse an existing browser session after the password has been verified. This flaw primarily affects versions 4.0.0 to 4.16.1 and enables the bypassing of Multi-Factor Authentication (MFA) steps under certain configurations, potentially exposing user accounts to unauthorized access. The vulnerability arises because session validity checks may not require MFA when the organization has not enforced it strictly. The issue has been addressed in version 4.16.1.

Affected Version(s)

zitadel >= 4.0.0, < 4.16.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.