ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover. | |
| Title | ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:04.626Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105211
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.333
Modified: 2026-10-04T15:16:32.467
Link: CVE-2026-105211
No data.
OpenCVE Enrichment
Updated: 2026-10-04T15:30:16Z
Weaknesses