Summary
CVE-2026-105211 is an authentication bypass vulnerability in ZITADEL’s Login V2 UI that allows an unauthenticated attacker who knows only a victim’s login name to obtain a fully MFA-authenticated session. The flaw stems from the returnCode OTP delivery type returning one-time passcodes directly in the HTTP response instead of sending them out-of-band, letting the attacker complete both OTP factors without any credentials. Exploitation can lead to full account takeover, including compromise of administrator accounts and the underlying ZITADEL instance.
Technical details
- Root cause: the Login V2 server-side flow exposes the
returnCodeOTP delivery type, which returns the generated OTP code directly in the server response rather than delivering it only to the victim’s email or phone. - Trigger conditions: the targeted account must have both OTP-Email and OTP-SMS registered as second factors; the attacker needs only the victim’s login name/username.
- Attack vector: network-accessible, no prior authentication or user interaction required; the attacker submits an identify-only session, requests OTP challenges via
returnCodefor both email and SMS factors, reads both codes from the responses, and submits them. - Impact: the backend’s MFA evaluation logic accepts two second factors as sufficient authentication, producing a session ZITADEL treats as MFA-authenticated without any primary factor (password, passkey, or IdP) ever being verified — resulting in account takeover and, for privileged accounts, full instance compromise.
Affected software
- ZITADEL 4.x versions 4.0.0 through 4.17.0 (including release candidates in that range)
Severity
- CVSS v4.0 Base Score: 9.2 (Critical) —
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1 Base Score (as also published): 8.1 (High) —
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade ZITADEL to version 4.17.1 or later, which prevents the browser from requesting OTP codes via
returnCodein the Login V2 flow. - If upgrading is not immediately possible: avoid enrolling both OTP-Email and OTP-SMS on the same account, particularly for privileged/administrative users, and prefer TOTP, U2F/security keys, or passkeys as second factors instead.

