๐Ÿ” CVE Alert

CVE-2026-105210

HIGH 8.2

ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.

CWE CWE-287
Vendor zitadel
Product zitadel
Published Oct 4, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new high vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

zitadel / zitadel
0 < 4.17.1
zitadel / zitadel
0 < 3.4.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-72q5-mv5c-vxv4 vulncheck.com: https://www.vulncheck.com/advisories/zitadel-before-4.17.1-unauthenticated-mfa-enrollment-via-login-v1-init-handlers

Credits

grvijayan livio-a ๐Ÿ” lucasdodgson ๐Ÿ” AdamKorcz