CVE-2026-105211: ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Affected Software
Event History
Frequently Asked Questions
Which accounts are exposed to takeover?
Accounts whose users have both OTP-Email and OTP-SMS enrolled are exposed when Login V2 is in use. Successful exploitation can yield an MFA-authenticated session, including for administrator accounts.
What does an attacker need to exploit this issue?
The attacker does not need to authenticate or interact with the victim. They need to know the victim's login name and target an account with OTP-Email and OTP-SMS enrolled, then obtain both OTP codes from server-action responses.
What version resolves the issue?
Upgrade to ZITADEL 4.17.1 or later. Versions before 4.17.1 are affected.