CVE-2026-85056
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL Due to Missing MFA Verification

Vulnerability report for CVE-2026-85056, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: GitHub, Inc.

Description

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization enables Force MFA or Force MFA for local users only, so a voluntarily enrolled factor can be skipped while completing an OIDC or SAML callback for a customer application. Login V1, the ZITADEL Console, Management and Admin APIs, and user self-management are not affected. This issue is fixed in version 4.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zitalel login_v2 From 4.0.0 (inc) to 4.16.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ZITADEL Login V2 from versions 4.0.0 to 4.16.1 creates a browser session after password verification but may reuse that session for later authentication without verifying enrolled second factors like TOTP, OTP, or U2F. This allows skipping MFA if the organization does not enforce Force MFA settings.

Detection Guidance

Detecting this vulnerability requires checking if your ZITADEL Login V2 version is between 4.0.0 and 4.16.1. Run: zitalel version. If the version falls within this range, the system is vulnerable.

Impact Analysis

An attacker could exploit this to gain unauthorized access to user accounts by bypassing multi-factor authentication, potentially leading to data breaches or unauthorized actions if MFA is not enforced by the organization.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA, which mandate strong authentication and access controls. Non-compliance risks legal penalties and reputational damage.

Mitigation Strategies

Upgrade ZITADEL Login V2 to version 4.16.1 or later immediately. This fixes the session reuse issue without MFA verification. Verify the update with: zitalel version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart