CVE-2026-105211
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL Login V2 via OTP Code Exposure

Vulnerability report for CVE-2026-105211, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
zitalel zitalel to 4.17.1 (exc)
zitadel zitadel to 4.17.1 (exc)
zitadel zitadel to 4.17.0 (inc)
zitadel zitadel 4.17.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ZITADEL before version 4.17.1 has an authentication bypass flaw in its Login V2 system. Unauthenticated attackers can take over user accounts by obtaining one-time password (OTP) codes through the returnCode delivery method. Attackers knowing a victim's login name with OTP-Email and OTP-SMS enrolled can retrieve both OTP codes from server responses, bypassing multi-factor authentication (MFA) and gaining full access, including administrative privileges.

Detection Guidance

To detect this vulnerability, check if your ZITADEL instance is running a version prior to 4.17.1. Use commands like 'zitadel version' or inspect deployment logs for version details. Monitor HTTP responses for OTP codes being returned directly in server actions with returnCode delivery type.

Impact Analysis

This vulnerability allows attackers to fully compromise accounts, including administrative ones, without needing the victim's password or interaction. It exposes sensitive data, enables unauthorized actions, and could lead to data breaches or system takeovers if exploited.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using vulnerable ZITADEL versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Immediately upgrade ZITADEL to version 4.17.1 or later. As a temporary measure, avoid enrolling both OTP-Email and OTP-SMS on the same account, especially for privileged users. Prefer using TOTP, security keys, or passkeys for MFA.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105211. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart