ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA. | |
| Title | ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:05.215Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105212
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.520
Modified: 2026-10-04T15:16:32.637
Link: CVE-2026-105212
No data.
OpenCVE Enrichment
Updated: 2026-10-04T16:15:15Z
Weaknesses