๐Ÿ” CVE Alert

CVE-2026-85056

HIGH 8.2

ZITADEL: MFA bypass via session reuse in Login V2

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization enables Force MFA or Force MFA for local users only, so a voluntarily enrolled factor can be skipped while completing an OIDC or SAML callback for a customer application. Login V1, the ZITADEL Console, Management and Admin APIs, and user self-management are not affected. This issue is fixed in version 4.16.1.

CWE CWE-287
Vendor zitadel
Product zitadel
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for zitadel zitadel

Be the first to know when new high vulnerabilities affecting zitadel zitadel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

zitadel / zitadel
>= 4.0.0, < 4.16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zitadel/zitadel/security/advisories/GHSA-9993-rfwp-rhwf github.com: https://github.com/zitadel/zitadel/commit/049dbb25a56587fb3980c85c99819cad69f637db github.com: https://github.com/zitadel/zitadel/commit/56f4798ed31fc1cfcd9a0e7f6f0152289d2fdc43 github.com: https://github.com/zitadel/zitadel/releases/tag/v4.16.1