Impact
ZITADEL versions prior to 4.17.1 contain a flaw in the Login V2 API that allows the returnCode delivery type to expose OTP codes to unauthenticated clients. By sending a login request with a known user name, an attacker can read the OTP‑Email and OTP‑SMS codes returned in the server’s action response. These codes enable the attacker to complete MFA and establish an authenticated session, effectively bypassing the authentication mechanism. The vulnerability can lead to complete account takeover, including administrator accounts, and is classified as a confidentiality and integrity breach (CWE‑200).
Affected Systems
The affected product is Zitadel Zitadel across all versions before 4.17.1. The CNA lists the product as "zitadel:zitadel" and the CPE indicates all versions. Any deployment using the default Login V2 endpoint on those versions is vulnerable. No specific subproduct details are provided, so the risk applies to any installation of Zitadel older than 4.17.1 that relies on the Login V2 OTP flow.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical severity. The EPSS score is not available, so the current public exploitation probability is unknown; however, the documented attack path is straightforward: send a login request and capture the OTP codes in the response. The vulnerability is not listed in the CISA KEV catalog, but the potential to gain privileged access makes it a high impact threat. Attackers can exploit it remotely through the public API or any client that can reach the login endpoint, and no special privileges or local access are required.
OpenCVE Enrichment