Back Redpacketsecurity CVE Alert: CVE-2026-105211 – zitadel
ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
**Risk verdict:** Treat this as a potentially critical identity-service exposure and urgently check whether affected deployments are present; KEV, SSVC exploitation, PoC and EPSS data are unavailable, so active exploitation cannot be confirmed.
**Why this matters:** Successful exploitation could give an attacker access to an account with its owner’s authentication assurance, enabling data theft, fraudulent changes or disruption. Administrative accounts are especially consequential because they can expose or alter identity infrastructure and user access.
**Most likely attack path:** The route is network-accessible, requires no prior privileges or user interaction, but has high complexity and a present attack requirement; an attacker also needs a target’s login name. The stated unchanged scope suggests impact is within the vulnerable service, though compromised administrative access could enable broader actions through legitimate management functions.
**Who is most exposed:** Organisations using the affected identity service for workforce or customer sign-in are at risk, particularly where it is internet-facing and protects privileged accounts. Confirm actual exposure and configuration rather than assuming all deployments are reachable.
Review application and proxy logs for unusual Login V2 OTP flows using `returnCode`.
Alert on server-action responses containing OTP-related data or unexpected response sizes.
Investigate anomalous successful sessions, especially for privileged accounts and unfamiliar locations.
Preserve relevant logs and check for suspicious account or authentication-setting changes.
Mitigation and prioritisation
Identify deployed releases and upgrade affected instances to the vendor-fixed release promptly.
Temporarily disable or restrict the implicated delivery behaviour if patching is delayed; test sign-in impact first.
Review privileged sessions and credentials; revoke suspicious sessions and rotate credentials where compromise is plausible.
Prioritise internet-facing identity services and document any change-control delay.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
