CVE Record
[ HIGH ]CVE-2026-105212
ZITADEL Login V1/V2 accepted passkey enrollment before auth
ZITADEL Login V1 and V2 accepted passkey or authenticator enrollment on identify-only login flows before identity was confirmed. Affects 3.x before 3.4.14 and 4.x before 4.16.2.
- Vendor
- ZITADEL
- Product
- ZITADEL (3.x before 3.4.14 and 4.x before 4.16.2)
- CVSS
- 7.5
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
ZITADEL’s Login V1 and V2 UIs accepted passkey and authenticator enrollment requests on identify-only login flows, before the user’s identity was confirmed. The flaw affects both login interface generations.
Affected: ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2.
Fixed in: 3.4.14 and 4.16.2.
Source: GHSA-45f2-5q3r-xgg6.
