ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows...

zetlyn/cve-ghsa vulnerability ghsa GHSA-mq63-7hcv-jfrc cve CVE-2026-105211 known 2026-10-04

https://github.com/advisories/GHSA-mq63-7hcv-jfrc

Properties

cvss8.1
receipt
Source
GitHub advisories
Its words
8.1
Read by
field:cvss.score
Said since
2026-10-04 18:14 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105211",
  "cvss": {
    "score": 8.1,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 8.1,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 9.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.",
  "ghsa_id": "GHSA-mq63-7hcv-jfrc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mq63-7hcv-jfrc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105211"
    }
  ],
  "nvd_published_at": "2026-10-04T15:16:32Z",
  "published_at": "2026-10-04T15:30:23Z",
  "references": [
    "https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105211",
    "https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode",
    "https://github.com/advisories/GHSA-mq63-7hcv-jfrc"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T15:30:29Z",
  "url": "https://api.github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-200
receipt
Source
GitHub advisories
Its words
CWE-200
Read by
field:cwes[].cwe_id
Said since
2026-10-04 18:14 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105211",
  "cvss": {
    "score": 8.1,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 8.1,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 9.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.",
  "ghsa_id": "GHSA-mq63-7hcv-jfrc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mq63-7hcv-jfrc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105211"
    }
  ],
  "nvd_published_at": "2026-10-04T15:16:32Z",
  "published_at": "2026-10-04T15:30:23Z",
  "references": [
    "https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105211",
    "https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode",
    "https://github.com/advisories/GHSA-mq63-7hcv-jfrc"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T15:30:29Z",
  "url": "https://api.github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitycritical
GitHub's own rating, from the CVSS base score at 9.0 and above.
receipt
Source
GitHub advisories
Its words
critical
Read by
field:severity
Said since
2026-10-04 18:14 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105211",
  "cvss": {
    "score": 8.1,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 8.1,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
    },
    "cvss_v4": {
      "score": 9.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.",
  "ghsa_id": "GHSA-mq63-7hcv-jfrc",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-mq63-7hcv-jfrc"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105211"
    }
  ],
  "nvd_published_at": "2026-10-04T15:16:32Z",
  "published_at": "2026-10-04T15:30:23Z",
  "references": [
    "https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105211",
    "https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode",
    "https://github.com/advisories/GHSA-mq63-7hcv-jfrc"
  ],
  "repository_advisory_url": null,
  "severity": "critical",
  "source_code_location": "",
  "summary": "ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T15:30:29Z",
  "url": "https://api.github.com/advisories/GHSA-mq63-7hcv-jfrc",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows... ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.