Skip to content
ZITADEL's 10-CVE Authentication Bypass Cluster Exposes the Self

ZITADEL's 10-CVE Authentication Bypass Cluster Exposes the Self

Forkast.News • October 5, 2026

A coordinated disclosure on October 4, 2026, exposed a critical authentication bypass cluster within the ZITADEL open-source identity provider . Spanning versions 3.x and 4.x, the vulnerability set includes seven critical-severity flaws, three high-severity issues, and one medium-severity vulnerability. These findings demonstrate a systemic failure in how identity state is managed, allowing unauthenticated actors to manipulate authentication flows before primary factor verification.

The technical core of this exposure is a recurring architectural failure: flow handlers within the ZITADEL codebase were found to be acting on accounts bound solely by a login name, prior to the verification of any authentication factor. This structural oversight effectively bypassed the primary security controls intended to gate access to sensitive operations. By failing to enforce a strict sequence of authentication, the system allowed unauthenticated or partially authenticated actors to interact with handlers that should have been protected.

The severity breakdown underscores the depth of the exposure. Among the critical vulnerabilities, CVE-2026-105209 (CVSS 9.6) allowed for cross-organization passkey enrollment. An attacker with user-write permissions in one organization could obtain an enrollment code for a user in a different organization on the same instance, register their own authenticator, and achieve full account takeover. Similarly, CVE-2026-105215 (CVSS 9.1) enabled unauthenticated account pre-hijacking in the Login V1 UI by trusting client-supplied external identity fields without a completed identity provider callback. CVE-2026-105214 (CVSS 9.1) introduced a server-side request forgery vector via organization domain HTTP verification, allowing attackers to scan internal networks or access cloud metadata.

Other critical flaws include CVE-2026-105211, which permitted MFA and OTP bypass in Login V2, and CVE-2026-105207, which allowed an unauthenticated attacker to bind their own identity to a victim’s account without primary factor verification. The high-severity vulnerabilities, such as CVE-2026-105212 and CVE-2026-105210, further demonstrate the danger of accepting enrollment or authentication actions on identify-only sessions. CVE-2026-105213 allowed users of deactivated organizations to maintain access, while CVE-2026-105208 exposed identity provider intent tokens to manipulation. A medium-severity flaw, CVE-2026-105206, enabled cross-organization user enumeration.

The risk is compounded by the lifecycle status of the software. The 3.x release line reached end-of-life on August 31, 2026, meaning it will receive no further security patches. Organizations still running self-hosted 3.x deployments are now in a state of permanent vulnerability unless they migrate to the 4.x branch. Given the historical tendency for self-hosted deployments to lag in patching cycles — a pattern observed in prior Zimbra signing key harvests and Bouncy Castle MLS spoofing — this transition period presents a significant window of exposure for enterprise environments.

This cluster serves as another instance of the trust-through-defaults failure pattern. When core identity components rely on implicit trust in client-supplied data or fail to enforce strict state-machine transitions, the entire security architecture collapses. The research, conducted by Michael Wollner of Deutsche Telekom AG, Adam Korczynski of Ada Logics with Anthropic, and several independent researchers, emphasizes that these are not edge cases but fundamental flaws in how identity state is managed.

The implications extend beyond traditional user access. As identity providers increasingly serve as the backbone for agentic workflows, the compromise of the identity layer propagates directly into automated systems. If an identity provider can be manipulated to bypass MFA or hijack sessions, the agents relying on those sessions for authorization inherit that exposure. In an environment where automated agents perform high-value tasks, the identity layer is the primary target for lateral movement and privilege escalation.

Remediation requires immediate action. For 4.x users, the full cluster is addressed in version 4.17.3, with initial fixes appearing in 4.16.2. Users on the 3.x branch must prioritize an upgrade to 4.x, as the 3.4.14 and 3.4.15 releases are insufficient for long-term security. Decision-makers should treat these patches not as routine maintenance, but as a critical hardening of their trust architecture. Proactive lifecycle management and a rigorous audit of how authentication flows are handled within the organization’s specific deployment configuration are now mandatory.