CVE Record
[ HIGH ]CVE-2026-105211
ZITADEL Login V2 OTP codes exposed via returnCode type
ZITADEL Login V2 allowed unauthenticated attackers to obtain OTP codes via the returnCode delivery type, enabling account takeover. Affects 4.x before 4.17.1.
- Vendor
- ZITADEL
- Product
- ZITADEL (4.x before 4.17.1; fixed in 4.17.1)
- CVSS
- 8.1
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
ZITADEL’s Login V2 UI contained an authentication bypass: the returnCode delivery type exposed OTP codes to unauthenticated callers, allowing account takeover without knowing the target user’s credentials.
Affected: ZITADEL 4.x before 4.17.1.
Fixed in: 4.17.1.
Source: GHSA-3gwm-5wx8-4gm6.
