ZITADEL’s hosted login UIs allowed an unauthenticated attacker who knows only a victim’s login name to register an attacker-controlled passkey (or other authenticator) on the victim’s account, then complete login as that user. Enrollment was accepted on an identify-only login session/request—after the username was submitted, but before any password or other primary factor was verified.
An attacker who knows a valid login name can take over the corresponding account without knowing the password, using an existing passkey, completing MFA, or interacting with the victim.
This affects applications that authenticate users through ZITADEL’s hosted Login V2 and/or legacy Login V1 UI (OIDC/SAML). Existing passwords or second factors on the account do not prevent enrollment of the additional attacker-controlled authenticator.
Legitimate passkey registration via emailed init/registration codes is unaffected in intent; the vulnerability was that login flows accepted enrollment without that proof of possession (or a prior authentication).
Systems running one of the following versions are affected:
4.x: 4.0.0 through 4.16.1 (including RC versions)
3.x: 3.0.0 through 3.4.13 (including RC versions)
The vulnerability has been addressed in the latest releases. Login V2 now requires a verified primary factor (or a legitimate onboarding/user-verification path) before authenticator enrollment. Login V1 no longer allows passwordless setup from an auth request and only accepts the emailed init-code registration path.
4.x : Upgrade to $\ge$ 4.16.2
3.x : Upgrade to $\ge$ 3.4.14
The recommended solution is to upgrade to a patched version. There is no configuration that fully closes this gap on unpatched versions.
If you have any questions or this advisory, please email us at [email protected]
Michael Wollner from Deutsche Telekom AG ( @Ibonok ) for reporting the Login V2 issue
Lucas Dodgson from InfoGuard Labs ( @lucasdodgson ) for independently reporting the Login V1 and Login V2 issues
Dor Konis , Feras Daragma and Peleg Wasserman from GE Vernova
Adam Korczynski from Ada Logics ( @AdamKorcz ) for reporting the Login V2 issue with the help of Anthropic
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
