Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in ZITADEL's login process allows unauthorized access to user accounts, including administrative privileges, by intercepting one-time passcodes. This issue affects the authentication mechanism of the ZITADEL platform, potentially enabling attackers to bypass multi-factor authentication and gain control of sensitive accounts. The primary concern is to confirm if ZITADEL is in use and assess any potential exposure.
- Attackers can bypass multi-factor authentication.
- Confirms ZITADEL is in use and potential exposure.
- Assess your ZITADEL deployment for relevance.
Attack Path
How an attacker could exploit the issue
An attacker can initiate an account takeover by leveraging a vulnerability in the Login V2 feature. This bypasses standard authentication, allowing them to obtain One-Time Passcodes (OTP) through the `returnCode` delivery method. By knowing a victim's login name and having either OTP-Email or OTP-SMS enrolled, an attacker can intercept these codes from server responses, ultimately gaining access to Multi-Factor Authentication (MFA) protected sessions, including administrator accounts.
- Unauthenticated access to login functionality.
- Intercepting OTP codes from server responses.
- Full account takeover, including administrator access.
Live Threat
Current exploitation, exposure, and threat context
An authentication bypass vulnerability in Login V2 could allow unauthenticated attackers to take over accounts by obtaining One-Time Password (OTP) codes. When supported by the advisory, attackers who know a victim's login name, and have OTP-Email and OTP-SMS enrolled for that victim, could read both codes from server-action responses to gain multi-factor authentication (MFA)-authenticated sessions. This could potentially include administrator accounts.
- User accounts and administrator sessions.
- Attackers obtain OTP codes from server responses.
- Unauthorized account access and control.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical authentication bypass vulnerability in ZITADEL impacts organizations relying on it for identity and access management. The first practical step is to identify all ZITADEL instances, confirm their exposure and criticality, and determine the accountable owner. Subsequent actions should be planned based on this risk assessment, potentially involving vendor coordination for a fix or implementing temporary risk reduction measures if immediate patching is not feasible.
- Platform or application owners should address.
- Verify ZITADEL instance exposure and criticality.
- Plan remediation based on risk assessment.