Sceawere

Vulnerability Detail

CVE-2026-105211UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ZITADEL Login V2 Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
5h ago
Vendor
zitadel
Product
zitadel
Attack Type
Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-04T15:16:32.333Z",
  "pubdate": "2026-10-04T15:16:32.333Z",
  "executiveSummary": "ZITADEL versions prior to 4.17.1 are susceptible to a critical authentication bypass vulnerability within the Login V2 component. This vulnerability allows an unauthenticated remote attacker to perform a full account takeover, including administrator accounts, by intercepting Multi-Factor Authentication (MFA) codes.\nThe flaw stems from the improper handling of server-action responses when the returnCode delivery mechanism is utilized for OTP-Email and OTP-SMS authentication factors. By exploiting this behavior, an attacker can bypass standard authentication workflows without possessing legitimate credentials or prior access.\nThe impact is severe, as successful exploitation grants the attacker a fully authenticated session, bypassing MFA requirements entirely. Because ZITADEL serves as an identity and access management (IAM) solution, this vulnerability poses a significant risk to the integrity and confidentiality of all integrated services and managed identities. No specific user interaction is required beyond knowledge of the victim's login identifier. Organizations utilizing affected ZITADEL versions are strongly advised to upgrade to version 4.17.1 or later immediately to remediate the exposure.",
  "technicalDetails": "The vulnerability resides within the Login V2 implementation of ZITADEL, specifically affecting how the application manages Multi-Factor Authentication (MFA) workflows involving OTP-Email and OTP-SMS delivery types. The root cause is an insecure information disclosure occurring through server-action responses.\nWhen a user attempts to authenticate and the system triggers a request for an OTP, the Login V2 logic may facilitate the return of the OTP code directly within the HTTP response body if the 'returnCode' delivery parameter is processed incorrectly by the server-side actions. This design flaw essentially turns the authentication verification mechanism into an information leak vector.\nThe attack flow proceeds as follows: 1. The attacker identifies a target account login name. 2. The attacker initiates the authentication process against the target account. 3. Upon reaching the MFA phase, if the account has OTP-Email or OTP-SMS enabled, the attacker influences the request to leverage the returnCode delivery type. 4. The ZITADEL server-side action, failing to sanitize or restrict the output, includes the generated OTP in the response payload returned to the client. 5. The attacker parses this response to retrieve the valid OTP. 6. The attacker submits the retrieved OTP to the Login V2 endpoint to finalize the authentication process.\nBecause the server verifies the provided code as legitimate, the system issues a valid session token to the attacker. This mechanism effectively bypasses the requirement for the attacker to possess access to the victim's secondary communication channels (email or SMS).\nThe vulnerability is accessible to unauthenticated attackers, requiring only the target's username/login identifier to initiate the flow. There are no additional privilege requirements for the attacker, as the exploit targets the authentication logic itself. The scope of impact is broad, potentially allowing an attacker to escalate privileges to administrative levels if the compromised account possesses such roles. The vulnerability affects ZITADEL versions prior to 4.17.1, where the Login V2 component remains susceptible to this information disclosure during the MFA challenge-response cycle."
}
CVE-2026-105211: ZITADEL Login V2 Authentication Bypass (HIGH Severity, CVSS: 8.1) | Sceawere