PatchSiren cyber security CVE debrief
CVE-2026-105212 zitadel CVE debrief
CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. The vulnerability allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA). This authentication bypass occurs in the hosted Login V1 and Login V2 UIs, where passkey or other authenticator enrollment is accepted on identify-only login sessions, before any primary factor is verified. The vulnerability could lead to unauthorized access and lateral movement within compromised environments. Defenders should prioritize verifying ZITADEL deployments for exposure
- Vendor
- zitadel
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for ZITADEL deployments, security teams, and administrators should be aware of this vulnerability and take necessary actions to verify exposure and apply patches or mitigations.
Why it matters
CVE-2026-105212 is a high-severity authentication bypass vulnerability in ZITADEL that allows unauthenticated attackers to bypass passwords and MFA, potentially leading to unauthorized access and lateral movement within compromised environments. Defenders should prioritize verifying ZITADEL deployments for exposure and applying vendor-provided patches or mitigations.
- Potential unauthorized access to sensitive data and systems.
- Bypassing of existing security controls, such as passwords and MFA.
- Possible lateral movement within compromised environments.
- Need for verification of ZITADEL deployments and application of patches or mitigations.
Technical summary
The vulnerability is caused by an authentication bypass in the hosted Login V1 and Login V2 UIs of ZITADEL, which accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. This allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA).
Defensive priority
Defenders should prioritize verifying ZITADEL deployments for exposure and applying vendor-provided patches or mitigations.
Recommended defensive actions
- Verify ZITADEL deployments for exposure by checking version numbers and configurations.
- Apply vendor-provided patches or mitigations to address the authentication bypass vulnerability.
- Monitor for suspicious login activity and implement additional security measures to detect potential exploitation attempts.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation and impact is limited. There is no evidence of public exploitation, but defenders should verify ZITADEL deployments for exposure and apply vendor-provided patches or mitigations. The vulnerability affects ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. Official CVE Program and NVD records offer limited context on potential impact and affected configurations. Defenders must review configurations and version numbers to assess
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105212 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105212
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105212 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105212
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/zitadel/zitadel/security/advisories/GHSA-45f2-5q3r-xgg6
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/zitadel-before-3.4.14-and-4.16.2-account-takeover-via-passkey-enrollment
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.