Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-105212

ZITADEL Login V1/V2 accepted passkey enrollment before auth

ZITADEL Login V1 and V2 accepted passkey or authenticator enrollment on identify-only login flows before identity was confirmed. Affects 3.x before 3.4.14 and 4.x before 4.16.2.

cat cve-2026-105212.json
Vendor
ZITADEL
Product
ZITADEL (3.x before 3.4.14 and 4.x before 4.16.2)
CVSS
7.5
EPSS (exploit probability)
0.3%
Status
patched
Published

ZITADEL’s Login V1 and V2 UIs accepted passkey and authenticator enrollment requests on identify-only login flows, before the user’s identity was confirmed. The flaw affects both login interface generations.

Affected: ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2.

Fixed in: 3.4.14 and 4.16.2.

Source: GHSA-45f2-5q3r-xgg6.