Sceawere
Vulnerability Detail
CVE-2026-105213UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ZITADEL Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 5h ago
- Vendor
- zitadel
- Product
- zitadel
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-04T15:16:32.687Z",
"pubdate": "2026-10-04T15:16:32.687Z",
"executiveSummary": "ZITADEL versions prior to 4.17.1 contain a critical authorization bypass vulnerability within the Login V2 authentication flow. The flaw resides in a failure to perform organizational-level state validation during the authentication process.\nSpecifically, while the system correctly verifies the status of individual user accounts, it fails to enforce a check on the 'inactive' status of the associated organization. Consequently, users belonging to a deactivated organization maintain the ability to authenticate, establish new sessions, and refresh existing security tokens.\nThis vulnerability exposes the system to unauthorized access by users who should be restricted due to organizational deactivation policies. An attacker possessing valid credentials or existing session material can circumvent organizational access controls, potentially accessing sensitive resources despite administrative efforts to disable the organizational unit. The risk is elevated as it permits continued activity for entities that the system administrator intended to fully isolate or suspend. Remediation requires an immediate update to version 4.17.1 or later to ensure that organizational state is rigorously evaluated during every authentication and token renewal attempt.",
"technicalDetails": "The root cause of this vulnerability is an incomplete authorization check within the Login V2 authentication pipeline of ZITADEL. In multi-tenant environments, security models must enforce hierarchical access controls where the status of the parent entity (the organization) supercedes the status of individual principals. The current implementation performs granular checks at the user object level but neglects to query or validate the lifecycle state of the parent organization object during the authentication handshake.\nThe attack flow begins when an administrator marks an organization as 'inactive' within the ZITADEL console. Under normal security logic, this transition should invalidate all active sessions associated with the organization and prevent further token issuance. However, because the Login V2 service only validates the specific user's status flag, the authentication logic fails to verify if the organization's state is set to 'active.'\nAn attacker can exploit this by utilizing pre-existing valid credentials or refresh tokens that were issued prior to the organization being deactivated. When the user submits these credentials or presents a refresh token to the authentication endpoint, the ZITADEL Login V2 component evaluates the user's account state, finds it to be active, and subsequently grants a new session or extends the life of an existing token. The logic completely bypasses the organizational state check, allowing the user to continue interacting with ZITADEL services.\nThe vulnerable component is the authentication service responsible for processing Login V2 requests. The flaw is present in all ZITADEL versions prior to 4.17.1. This represents a significant failure in secure session management and access control enforcement, as it effectively renders the organizational deactivation feature ineffective against persistent or knowledgeable users. The ability to successfully refresh tokens allows an attacker to maintain long-term unauthorized access to the environment, bypassing the intended security posture enforced by organizational-level administrative actions."
}