Impact
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 have a flaw in the hosted Login V1 user interface: the second‑factor enrollment and initialization handlers are triggered on an identify‑only session that has not yet verified any primary authentication factor. Because of this missing check, an attacker who knows a victim’s username can enroll attacker‑controlled TOTP, OTP‑SMS, OTP‑Email, or U2F factors, overwrite the verified phone number, and gain full control of the victim account. The attacker can therefore impersonate the victim and potentially perform privileged actions. Additionally, users can be enumerated through differing error responses.
Affected Systems
ZITADEL ZITADEL servers running version 3.x prior to 3.4.15 or version 4.x prior to 4.17.1 are vulnerable. Ensure you test your deployment against these version ranges.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the missing authentication check provides a classic remote, unauthenticated attack vector against a web interface. An attacker only needs to know the victim’s login name and can then interact with the exposed endpoints over the network. Because the flaw is exposed through a publicly reachable web UI, the likelihood of exploitation is significant in environments that expose ZITADEL services to the internet.
OpenCVE Enrichment