Summary
CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL’s hosted Login V1 and Login V2 UIs that allows an unauthenticated attacker to enroll a malicious passkey (or other authenticator) on an "identify-only" login session — one where the username has been submitted but no primary factor (password) has yet been verified. Knowing only a victim’s login name, an attacker can register their own authenticator and fully take over the account, bypassing the victim’s existing password and any configured MFA. The issue is rated HIGH severity (CVSS 8.7).
Technical details
- Root cause: The hosted Login V1/V2 flow permits authenticator (passkey) enrollment on a login session that has only completed the "identify" step (username submitted) and has not yet verified a primary authentication factor.
- Trigger conditions: An attacker submits a known or guessed victim username to start a login session, then invokes the authenticator-enrollment step before any password or other primary factor check occurs.
- Attack vector: Network-based, no authentication or user interaction required (CWE-287: Improper Authentication; CWE-306: Missing Authentication for Critical Function).
- Impact: Full account takeover — the attacker-registered passkey can be used to log in as the victim, independent of the victim’s real password or MFA configuration. No victim interaction is needed.
Affected software
- ZITADEL 4.x: versions 4.0.0 through 4.16.1
- ZITADEL 3.x: versions 3.0.0 through 3.4.13
Severity
- CVSS 4.0: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS 3.1: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade to ZITADEL 4.16.2 or later (4.x branch), or 3.4.14 or later (3.x branch).
- If no patch can be applied immediately: No effective configuration-based workaround exists per the vendor advisory; restrict or closely monitor exposure of the hosted Login V1/V2 endpoints until the upgrade is applied, and review authenticator/passkey enrollment logs for unexpected registrations tied to identify-only sessions.

