Back Redpacketsecurity CVE Alert: CVE-2026-105212 – zitadel
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim’s login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.
**Risk verdict:** High-risk account compromise is possible over the network without prior access; urgency rises if exposed login services are affected, but KEV and SSVC status were not supplied.
**Why this matters:** An attacker may gain control of a named user’s account, bypassing their established authentication. This could expose sensitive identity data and provide a foothold into connected applications, although direct service disruption or changes to data are not indicated by the impact scores.
**Most likely attack path:** The attack requires network reachability but, based on the supplied metrics, no special conditions, existing privileges or victim interaction. Scope is unchanged, so the flaw does not itself indicate impact across a security boundary; however, access granted by the compromised identity may enable further activity in connected systems.
**Who is most exposed:** Organisations running internet-accessible hosted login flows and allowing users to enrol authenticators are the principal concern. Prioritise identity services used by staff, customers or administrators.
Review authenticator-enrolment and sign-in audit events for unexpected pairings.
Alert on enrolment followed by successful login without evidence of primary-factor verification.
Correlate unusual source IPs, locations and targeted account names.
Check for recently added authenticators on privileged accounts.
Mitigation and prioritisation:
Upgrade to a fixed release on the applicable supported branch; confirm the deployed build.
Until patched, restrict authenticator enrolment or require verified primary authentication first.
Revoke suspicious enrolments and reset affected sessions; investigate account activity.
Test login and enrolment flows after changes, with rollback planning.
KEV and EPSS were not provided; if KEV is confirmed or EPSS is at least 0.5, treat as priority 1.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
