CVE-2026-105213
Deferred Deferred - Pending Action

Authentication Bypass in ZITADEL Due to Inactive Organization Check

Vulnerability report for CVE-2026-105213, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zitadel zitadel to 4.17.1 (exc)
zitadel zitadel to 4.17.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105213 is an authentication bypass vulnerability in ZITADEL versions before 4.17.1. It allows users from deactivated organizations to log in successfully if their individual account is active. The flaw occurs because Login V2 does not check the organization's inactive state, only verifying the user's status.

Detection Guidance

To detect this vulnerability, check if your ZITADEL instance is running versions 4.0.0 through 4.17.0. Verify if users from deactivated organizations can still authenticate via Login V2. Review authentication logs for successful logins from users whose organizations are marked inactive.

Impact Analysis

This vulnerability could allow unauthorized access to systems for users whose organizations are deactivated. Attackers with valid credentials or existing sessions could maintain access, create new sessions, or refresh tokens even after an organization is deactivated. This poses a risk of continued unauthorized use of resources.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection and privacy requirements under GDPR and HIPAA. It undermines access control measures, potentially resulting in non-compliance with security and privacy standards that require proper deactivation and access revocation.

Mitigation Strategies

Immediately upgrade ZITADEL to version 4.17.1 or later. If upgrading is not possible, deactivate affected user accounts individually and revoke all active sessions and tokens for users in deactivated organizations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105213. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart