Description
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Published: 2026-10-04
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass / Account Takeover
Action: Immediate Patch
AI Analysis

Impact

ZITADEL versions prior to 4.17.1 contain a flaw in the Login V2 API that allows the returnCode delivery type to expose OTP codes to unauthenticated clients. By sending a login request with a known user name, an attacker can read the OTP‑Email and OTP‑SMS codes returned in the server’s action response. These codes enable the attacker to complete MFA and establish an authenticated session, effectively bypassing the authentication mechanism. The vulnerability can lead to complete account takeover, including administrator accounts, and is classified as a confidentiality and integrity breach (CWE‑200).

Affected Systems

The affected product is Zitadel Zitadel across all versions before 4.17.1. The CNA lists the product as "zitadel:zitadel" and the CPE indicates all versions. Any deployment using the default Login V2 endpoint on those versions is vulnerable. No specific subproduct details are provided, so the risk applies to any installation of Zitadel older than 4.17.1 that relies on the Login V2 OTP flow.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical severity. The EPSS score is not available, so the current public exploitation probability is unknown; however, the documented attack path is straightforward: send a login request and capture the OTP codes in the response. The vulnerability is not listed in the CISA KEV catalog, but the potential to gain privileged access makes it a high impact threat. Attackers can exploit it remotely through the public API or any client that can reach the login endpoint, and no special privileges or local access are required.

Generated by OpenCVE AI on October 4, 2026 at 15:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to zitadel 4.17.1 or later
  • Invalidate all existing OTP codes for accounts enrolled with OTP-Email and OTP-SMS
  • Audit login logs and monitor for suspicious OTP usage

Generated by OpenCVE AI on October 4, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Title ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-200
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:04.626Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105211

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:32.333

Modified: 2026-10-04T15:16:32.467

Link: CVE-2026-105211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T17:45:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor