Description
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Published: 2026-10-04
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

ZITADEL versions prior to 4.17.1 fail to verify an organization’s inactive status during Login V2 authentication, checking only the individual user’s state. As a result, any user belonging to a deactivated organization who possesses valid credentials, an existing session, or a refresh token can sign in, create new sessions, and obtain or refresh tokens. This flaw enables unauthorized access and could allow an attacker to retrieve confidential data, modify resources, or perform actions with the user’s privileges.

Affected Systems

The affected product is ZITADEL, the identity management platform created by ZITADEL. All releases that belong to the 4.x series and precede version 4.17.1 are impacted; the exact sub‑versions are not enumerated in the advisory, so any build before 4.17.1 should be considered vulnerable.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity. No EPSS score is available, but the lack of mitigating factors and the straightforward nature of the bypass suggest a non‑negligible likelihood of exploitation. The vulnerability is listed as not being in CISA’s KEV catalog. Attackers can exploit it remotely by issuing Login V2 requests over the network; the only prerequisite is possession of valid credentials or token artifacts for a user within a deactivated organization, making the attack accessible to anyone who can acquire such credentials or tokens.

Generated by OpenCVE AI on October 4, 2026 at 15:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZITADEL to version 4.17.1 or later, which implements a check for organization active status during Login V2.
  • Revoke all refresh tokens and active sessions for users who belong to deactivated organizations to eliminate existing footholds.
  • Configure or enforce deactivation controls so that deactivated organizations are blocked from authentication attempts, for example by adjusting IAM settings or adding middleware that rejects requests from inactive orgs.

Generated by OpenCVE AI on October 4, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Title ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
First Time appeared Zitadel
Zitadel zitadel
Weaknesses CWE-287
CPEs cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:*
Vendors & Products Zitadel
Zitadel zitadel
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T13:10:05.815Z

Reserved: 2026-10-04T13:02:21.188Z

Link: CVE-2026-105213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-04T15:16:32.687

Modified: 2026-10-04T15:16:32.800

Link: CVE-2026-105213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T16:15:15Z

Weaknesses