External risk intelligence

ZITADEL Login V2 Authentication Bypass Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-105211

ZITADEL is an identity and access management (IAM) solution designed to be deployed as an internet-facing service for authentication, single sign-on, and user management. As an identity provider, it acts as a public-facing gateway for user logins, making its authentication endpoints inherently reachable from the internet in standard deployments.

Information Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in ZITADEL's login process allows unauthorized access to user accounts, including administrative privileges, by intercepting one-time passcodes. This issue affects the authentication mechanism of the ZITADEL platform, potentially enabling attackers to bypass multi-factor authentication and gain control of sensitive accounts. The primary concern is to confirm if ZITADEL is in use and assess any potential exposure.

  • Attackers can bypass multi-factor authentication.
  • Confirms ZITADEL is in use and potential exposure.
  • Assess your ZITADEL deployment for relevance.

Attack Path

How an attacker could exploit the issue

An attacker can initiate an account takeover by leveraging a vulnerability in the Login V2 feature. This bypasses standard authentication, allowing them to obtain One-Time Passcodes (OTP) through the `returnCode` delivery method. By knowing a victim's login name and having either OTP-Email or OTP-SMS enrolled, an attacker can intercept these codes from server responses, ultimately gaining access to Multi-Factor Authentication (MFA) protected sessions, including administrator accounts.

  • Unauthenticated access to login functionality.
  • Intercepting OTP codes from server responses.
  • Full account takeover, including administrator access.

Live Threat

Current exploitation, exposure, and threat context

An authentication bypass vulnerability in Login V2 could allow unauthenticated attackers to take over accounts by obtaining One-Time Password (OTP) codes. When supported by the advisory, attackers who know a victim's login name, and have OTP-Email and OTP-SMS enrolled for that victim, could read both codes from server-action responses to gain multi-factor authentication (MFA)-authenticated sessions. This could potentially include administrator accounts.

  • User accounts and administrator sessions.
  • Attackers obtain OTP codes from server responses.
  • Unauthorized account access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical authentication bypass vulnerability in ZITADEL impacts organizations relying on it for identity and access management. The first practical step is to identify all ZITADEL instances, confirm their exposure and criticality, and determine the accountable owner. Subsequent actions should be planned based on this risk assessment, potentially involving vendor coordination for a fix or implementing temporary risk reduction measures if immediate patching is not feasible.

  • Platform or application owners should address.
  • Verify ZITADEL instance exposure and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZITADEL used for?

ZITADEL is an identity and access management (IAM) solution. Organizations use it as a centralized gateway to handle user authentication, single sign-on (SSO), and lifecycle management for their applications and services.

What is the CVE-2026-105211 weakness?

This vulnerability is classified as CWE-200, which involves the improper exposure of sensitive information. In this specific case, the Login V2 feature mistakenly includes secret one-time passcodes (OTP) within server-action responses, allowing an unauthorized party to read them.

How does an attacker trigger this vulnerability?

An attacker needs the victim's login name and must target an account where OTP-Email or OTP-SMS is enabled. If these conditions are met, the attacker requests the login and reads the OTP code directly from the server's response. Note that if the victim does not have these specific MFA methods enrolled, this specific bypass path is not available.

Why should I care about this CVE?

Halo Surface Signal indicates that ZITADEL is designed as an internet-facing service for identity management. Because its authentication endpoints are typically reachable from the public internet, any deployment using the affected Login V2 feature is inherently at risk of account takeover, including the potential compromise of administrative sessions.

How do I respond to CVE-2026-105211?

Begin by auditing your environment to identify all ZITADEL instances and confirm if they utilize the vulnerable Login V2 feature. Once you have mapped your deployments, determine the criticality of each instance and coordinate with the relevant system owners to plan for updates or implement temporary security controls to mitigate unauthorized access.

References