Description
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.
Published: 2026-10-04
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Impersonation via unauthorized MFA enrollment
Action: Immediate Patch
AI Analysis

Impact

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 have a flaw in the hosted Login V1 user interface: the second‑factor enrollment and initialization handlers are triggered on an identify‑only session that has not yet verified any primary authentication factor. Because of this missing check, an attacker who knows a victim’s username can enroll attacker‑controlled TOTP, OTP‑SMS, OTP‑Email, or U2F factors, overwrite the verified phone number, and gain full control of the victim account. The attacker can therefore impersonate the victim and potentially perform privileged actions. Additionally, users can be enumerated through differing error responses.

Affected Systems

ZITADEL ZITADEL servers running version 3.x prior to 3.4.15 or version 4.x prior to 4.17.1 are vulnerable. Ensure you test your deployment against these version ranges.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the missing authentication check provides a classic remote, unauthenticated attack vector against a web interface. An attacker only needs to know the victim’s login name and can then interact with the exposed endpoints over the network. Because the flaw is exposed through a publicly reachable web UI, the likelihood of exploitation is significant in environments that expose ZITADEL services to the internet.

Generated by OpenCVE AI on October 4, 2026 at 15:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to version 3.4.15 or later, or version 4.17.1 or later, which removes the unauthenticated MFA enrollment flaw.
  • Restrict or disable unauthenticated access to the Login V1 UI endpoints that handle MFA enrollment until the patched version is deployed, ensuring that only authenticated sessions can initiate MFA provisioning.
  • Enable rate limiting and log monitoring on the MFA enrollment and initialization endpoints to detect abuse patterns and reduce the risk of enumeration or credential stuffing attacks.

Generated by OpenCVE AI on October 4, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.
Title ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-287
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:03.949Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:32.170

Modified: 2026-10-04T15:16:32.287

Link: CVE-2026-105210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T16:30:15Z

Weaknesses