CRITICAL 9.2 NVD

CVE-2026-105211

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP c

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

References

Published: 2026-10-04 · Source: NVD · Feed updated: 2026-10-04
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-10-04 via NVD.

Risk Timeline

CVE Disclosed2026-10-04 · -1 days ago

Remediation Resources

vulnfeed aggregates 10549 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.