CVE-2026-105210
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL Login V1 UI

Vulnerability report for CVE-2026-105210, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 3.4.15 (exc)
zitadel zitadel to 4.17.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 allows unauthenticated attackers who know a victim's login name to manipulate Multi-Factor Authentication (MFA) enrollment and phone numbers. The issue occurs because the MFA enrollment handlers work on an identify-only session before the primary authentication factor (like a password) is verified. Attackers can enroll their own second factors (TOTP, OTP-SMS, OTP-Email, or U2F), overwrite the victim's verified phone number, and enumerate users through error discrepancies.

The vulnerability is specific to Login V1 and does not affect Login V2. Affected versions include ZITADEL 4.0.0 to 4.17.0 and 3.0.0 to 3.4.14. It has been patched in versions 4.17.1 and 3.4.15.

Detection Guidance

To detect this vulnerability, check if your ZITADEL instance is running an affected version (3.x before 3.4.15 or 4.x before 4.17.1). Verify if Login V1 UI is enabled and exposed to the internet. Monitor logs for unusual MFA enrollment attempts or phone number changes without primary authentication. No specific commands are provided in the resources.

Impact Analysis

Attackers can compromise account integrity by enrolling their own second factors or overwriting the victim's phone number. This could lead to unauthorized access if the attacker receives verification codes. User enumeration is also possible, as the system returns different errors for existing versus non-existing accounts.

However, the vulnerability does not allow attackers to learn the victim's password or directly take over the account. Password resets are email-only, limiting the impact. The attack requires no privileges, no user interaction, and is remotely exploitable over a network.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to potential breaches of confidentiality and integrity. Attackers can enroll unauthorized MFA methods or overwrite phone numbers, risking unauthorized access to sensitive data. GDPR requires protecting personal data integrity and confidentiality, while HIPAA mandates safeguarding protected health information. The user enumeration aspect may also violate data minimization principles under GDPR.

Mitigation Strategies

Immediately upgrade ZITADEL to version 3.4.15 or later for 3.x, or 4.17.1 or later for 4.x. Disable Login V1 UI if possible, as the vulnerability is specific to it. Ensure no unauthenticated MFA enrollments or phone number changes are allowed. Monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105210. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart