Skip to content
ZITADEL Vulnerabilities Enable Account Takeover via MFA Bypass

ZITADEL Vulnerabilities Enable Account Takeover via MFA Bypass

First seen 4 Oct 2026, 21:02 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 22:01 UTC
  • •ZITADEL vulnerabilities allow account takeover with just a login name.
  • •Attackers can bypass MFA by exploiting flaws in Login V1 and V2.
  • •Patches have been released, but the vulnerabilities were disclosed today.

ZITADEL's hosted Login UIs have multiple vulnerabilities allowing unauthenticated attackers to take over user accounts. Attackers can exploit these flaws by knowing only the victim's login name, enabling them to obtain MFA-authenticated sessions or enroll attacker-controlled second factors. The vulnerabilities affect both Login V1 and Login V2 UIs, with specific methods for each version. Login V1 allows attackers to overwrite verified phone numbers and enroll second factors, while Login V2 enables session hijacking using OTP codes. These vulnerabilities impact users who have OTP-Email and OTP-SMS enrolled. Patches have been released to address these issues, but the vulnerabilities were disclosed on October 4, 2026. The flaws are significant due to the potential for complete account takeover, especially for administrative accounts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
ZITADEL vulnerabilities disclosed
Multiple vulnerabilities in ZITADEL's Login UIs were disclosed, allowing account takeover via MFA bypass.
github.com
2026-10-04
Patches released
ZITADEL released patches to address the vulnerabilities in both Login V1 and Login V2 UIs.
github.com

More articles in this cluster (3)

Following this threat?

Track Zitadel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are the main vulnerabilities?
The vulnerabilities allow attackers to take over accounts by exploiting flaws in the Login V1 and V2 UIs without needing a password.
What should users do to protect themselves?
Users should apply the latest patches released by ZITADEL to mitigate these vulnerabilities.
Are these vulnerabilities actively exploited?
No confirmed active exploitation has been reported, but the vulnerabilities have been disclosed and patched.