CVE-2026-105211 PUBLISHED

ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode

Assigner: VulnCheck
Reserved: 04.10.2026 Published: 04.10.2026 Updated: 05.10.2026

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor zitadel
Product zitadel
Versions Default: unaffected
  • affected from 0 to 4.17.1 (excl.)
  • Version 4.17.1 is unaffected

Credits

  • IAM-marco finder
  • livio-a finder
  • lucasdodgson reporter

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE