CVE-2026-105211
9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zitadel | zitadel | 0 < 4.17.1 | affected |
| zitadel | zitadel | 4.17.1 | unaffected |
Weaknesses
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6
- https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.