High severity8.1NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026
CVE-2026-105211
CVE-2026-105211
Description
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.