Summary
CVE-2026-105210 is an authentication bypass vulnerability in ZITADEL’s hosted Login V1 UI, rated HIGH severity (CVSS 8.8 / 8.2 depending on scoring version). The flaw allows an unauthenticated attacker who knows only a victim’s login name to enroll attacker-controlled second-factor (MFA) credentials and overwrite the victim’s verified phone number, without ever supplying a valid password or other primary authentication factor.
Technical details
- Root cause: The Login V1 UI’s second-factor enrollment and initialization handlers operate on an "identify-only" login session — a session created once a username is submitted, but before any primary factor (password, passkey, etc.) has been verified.
- Trigger condition: An attacker submits a known or guessed login name to reach the identify-only session state, then directly invokes the MFA enrollment/initialization endpoints that should only be reachable after primary authentication.
- Attack vector: Network-based, requires no privileges and no user interaction (CVSS AV:N/PR:N/UI:N).
- Impact: Attackers can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F second factors on the victim’s account, overwrite a previously verified phone number, and enumerate valid usernames via inconsistent error responses. This can lead to full account takeover by allowing the attacker to satisfy MFA checks with their own enrolled factor.
- Scope: Affects the Login V1 flow only (instance-scoped, cross-organization within an instance, not cross-instance); ZITADEL’s Login V2 flow is not affected by this issue.
Affected software
- ZITADEL 4.x: versions 4.0.0 through 4.17.0 (including release candidates)
- ZITADEL 3.x: versions 3.0.0 through 3.4.14 (including release candidates)
Severity
- CVSS v3.1 Base Score: 8.2 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N - CVSS v4.0 Base Score: 8.8 (High) — reflects Network attack vector, Low attack complexity, no privileges or user interaction required
Mitigation and recommended actions
- Immediate: Upgrade to ZITADEL 4.17.1 or later (for 4.x deployments), or 3.4.15 or later (for 3.x deployments).
- If no patch can be applied immediately: There is no configuration option that fully mitigates this issue on unpatched versions — upgrading is the only complete remediation. Organizations that cannot upgrade immediately should restrict or monitor exposure of the hosted Login V1 UI and closely review account activity for unexpected MFA enrollment or phone number changes.

