CRITICAL 9.2 NVD
CVE-2026-105211
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP c
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6
- https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-10-04 via NVD.
Risk Timeline
CVE Disclosed2026-10-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 10549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.