Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-105211

ZITADEL Login V2 OTP codes exposed via returnCode type

ZITADEL Login V2 allowed unauthenticated attackers to obtain OTP codes via the returnCode delivery type, enabling account takeover. Affects 4.x before 4.17.1.

cat cve-2026-105211.json
Vendor
ZITADEL
Product
ZITADEL (4.x before 4.17.1; fixed in 4.17.1)
CVSS
8.1
EPSS (exploit probability)
0.3%
Status
patched
Published

ZITADEL’s Login V2 UI contained an authentication bypass: the returnCode delivery type exposed OTP codes to unauthenticated callers, allowing account takeover without knowing the target user’s credentials.

Affected: ZITADEL 4.x before 4.17.1.

Fixed in: 4.17.1.

Source: GHSA-3gwm-5wx8-4gm6.