---
id: CVE-2026-105211
title: >-
  ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login
  V2 that allows unauthenticated attackers to take over accounts by obtaining
  OTP codes via the returnCode delivery type
summary: >-
  ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login
  V2 that allows unauthenticated attackers to take over accounts by obtaining
  OTP codes via the returnCode delivery type. Attackers knowing a login name of
  a vi…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-200
vendor: zitadel
product: zitadel
affected:
  - zitadel < 4.17.1
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T15:16:32.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105211'
references:
  - url: 'https://github.com/zitadel/zitadel/security/advisories/GHSA-3gwm-5wx8-4gm6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zitadel-before-4.17.1-authentication-bypass-via-login-v2-otp-returncode
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T15:00:34.390Z'
---

## Overview

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
