ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens. | |
| Title | ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:05.815Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105213
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.687
Modified: 2026-10-04T15:16:32.800
Link: CVE-2026-105213
No data.
OpenCVE Enrichment
Updated: 2026-10-04T16:15:15Z
Weaknesses