Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-105210 – Authentication Bypass (Unauthenticated MFA Enrollment) – ZITADEL Login V1 UI, 3.x

Be the first to know when new zero-days emerge:

Summary

CVE-2026-105210 is an authentication bypass vulnerability in ZITADEL’s hosted Login V1 UI, rated HIGH severity (CVSS 8.8 / 8.2 depending on scoring version). The flaw allows an unauthenticated attacker who knows only a victim’s login name to enroll attacker-controlled second-factor (MFA) credentials and overwrite the victim’s verified phone number, without ever supplying a valid password or other primary authentication factor.

Technical details

  • Root cause: The Login V1 UI’s second-factor enrollment and initialization handlers operate on an "identify-only" login session — a session created once a username is submitted, but before any primary factor (password, passkey, etc.) has been verified.
  • Trigger condition: An attacker submits a known or guessed login name to reach the identify-only session state, then directly invokes the MFA enrollment/initialization endpoints that should only be reachable after primary authentication.
  • Attack vector: Network-based, requires no privileges and no user interaction (CVSS AV:N/PR:N/UI:N).
  • Impact: Attackers can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F second factors on the victim’s account, overwrite a previously verified phone number, and enumerate valid usernames via inconsistent error responses. This can lead to full account takeover by allowing the attacker to satisfy MFA checks with their own enrolled factor.
  • Scope: Affects the Login V1 flow only (instance-scoped, cross-organization within an instance, not cross-instance); ZITADEL’s Login V2 flow is not affected by this issue.

Affected software

  • ZITADEL 4.x: versions 4.0.0 through 4.17.0 (including release candidates)
  • ZITADEL 3.x: versions 3.0.0 through 3.4.14 (including release candidates)

Severity

  • CVSS v3.1 Base Score: 8.2 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  • CVSS v4.0 Base Score: 8.8 (High) — reflects Network attack vector, Low attack complexity, no privileges or user interaction required

Mitigation and recommended actions

  • Immediate: Upgrade to ZITADEL 4.17.1 or later (for 4.x deployments), or 3.4.15 or later (for 3.x deployments).
  • If no patch can be applied immediately: There is no configuration option that fully mitigates this issue on unpatched versions — upgrading is the only complete remediation. Organizations that cannot upgrade immediately should restrict or monitor exposure of the hosted Login V1 UI and closely review account activity for unexpected MFA enrollment or phone number changes.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge