CVE-2026-105211
Deferred
Deferred - Pending Action
Authentication Bypass in ZITADEL Login V2 via OTP Code Exposure
Vulnerability report for CVE-2026-105211, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-04
Last updated on: 2026-10-04
Assigner: VulnCheck
Description
Description
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zitalel | zitalel | to 4.17.1 (exc) |
| zitadel | zitadel | to 4.17.1 (exc) |
| zitadel | zitadel | to 4.17.0 (inc) |
| zitadel | zitadel | 4.17.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |