CVE-2026-105212
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL Login UIs

Vulnerability report for CVE-2026-105212, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 3.4.14 (exc)
zitadel zitadel to 4.16.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in ZITADEL's hosted Login V1 and Login V2 UIs. It allows unauthenticated attackers who know a victim's login name to register an attacker-controlled passkey or authenticator without verifying the primary authentication factor like a password or MFA. This leads to full account takeover.

Detection Guidance

Check ZITADEL version with: curl -s https://your-zitadel-instance.com/debug/version | grep version. If version is below 3.4.14 or 4.16.2, the system is vulnerable. Review authentication logs for unusual passkey enrollment attempts during identify-only sessions.

Impact Analysis

Attackers can gain unauthorized access to your ZITADEL account by exploiting this flaw. They only need to know your login name to register their own authenticator and bypass existing passwords or MFA. This could lead to data theft, unauthorized actions, or complete account compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using unpatched ZITADEL versions may face compliance breaches, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade ZITADEL to version 3.4.14 or 4.16.2 or later immediately. No configuration workaround exists for unpatched versions. Monitor for unauthorized authenticator enrollments and disable Login V1 if possible until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105212. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart