PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105212 zitadel CVE debrief

CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. The vulnerability allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA). This authentication bypass occurs in the hosted Login V1 and Login V2 UIs, where passkey or other authenticator enrollment is accepted on identify-only login sessions, before any primary factor is verified. The vulnerability could lead to unauthorized access and lateral movement within compromised environments. Defenders should prioritize verifying ZITADEL deployments for exposure

Vendor
zitadel
Product
Unknown
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for ZITADEL deployments, security teams, and administrators should be aware of this vulnerability and take necessary actions to verify exposure and apply patches or mitigations.

Why it matters

CVE-2026-105212 is a high-severity authentication bypass vulnerability in ZITADEL that allows unauthenticated attackers to bypass passwords and MFA, potentially leading to unauthorized access and lateral movement within compromised environments. Defenders should prioritize verifying ZITADEL deployments for exposure and applying vendor-provided patches or mitigations.

  • Potential unauthorized access to sensitive data and systems.
  • Bypassing of existing security controls, such as passwords and MFA.
  • Possible lateral movement within compromised environments.
  • Need for verification of ZITADEL deployments and application of patches or mitigations.

Technical summary

The vulnerability is caused by an authentication bypass in the hosted Login V1 and Login V2 UIs of ZITADEL, which accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. This allows unauthenticated attackers to register an attacker-controlled authenticator and log in as a victim user, bypassing existing passwords and multi-factor authentication (MFA).

Defensive priority

Defenders should prioritize verifying ZITADEL deployments for exposure and applying vendor-provided patches or mitigations.

Recommended defensive actions

  • Verify ZITADEL deployments for exposure by checking version numbers and configurations.
  • Apply vendor-provided patches or mitigations to address the authentication bypass vulnerability.
  • Monitor for suspicious login activity and implement additional security measures to detect potential exploitation attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on exploitation and impact is limited. There is no evidence of public exploitation, but defenders should verify ZITADEL deployments for exposure and apply vendor-provided patches or mitigations. The vulnerability affects ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2. Official CVE Program and NVD records offer limited context on potential impact and affected configurations. Defenders must review configurations and version numbers to assess

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105212 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105212

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105212 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105212

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.