ZITADEL Vulnerabilities Enable Account Takeover via MFA Bypass
Article Content
- •ZITADEL vulnerabilities allow account takeover with just a login name.
- •Attackers can bypass MFA by exploiting flaws in Login V1 and V2.
- •Patches have been released, but the vulnerabilities were disclosed today.
ZITADEL's hosted Login UIs have multiple vulnerabilities allowing unauthenticated attackers to take over user accounts. Attackers can exploit these flaws by knowing only the victim's login name, enabling them to obtain MFA-authenticated sessions or enroll attacker-controlled second factors. The vulnerabilities affect both Login V1 and Login V2 UIs, with specific methods for each version. Login V1 allows attackers to overwrite verified phone numbers and enroll second factors, while Login V2 enables session hijacking using OTP codes. These vulnerabilities impact users who have OTP-Email and OTP-SMS enrolled. Patches have been released to address these issues, but the vulnerabilities were disclosed on October 4, 2026. The flaws are significant due to the potential for complete account takeover, especially for administrative accounts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Zitadel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the main vulnerabilities?
What should users do to protect themselves?
Are these vulnerabilities actively exploited?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…