Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105210— ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers

Quick assessment

Affected
zitadel zitadel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ZITADEL 3.x(3.4.15 之前版本)和 4.x(4.17.1 之前版本)在托管登录界面 V1(Hosted Login V1 UI)中存在一个缺失认证(Missing Authentication)漏洞。该漏洞的二次因子注册与初始化处理程序在尚未验证任何主认证因子(primary factor)的情况下,仅基于标识(identity-only)会话即进行操作。攻击者若仅知晓受害者的登录名称,即可注册由攻击者控制的 TOTP、OTP-SMS、OTP-Email 或 U2F 二次认证因子,覆盖已验证的电话号

CVSS 8.2 · High

Affected Version Matrix 4

VendorProduct Version RangeStatus
zitadel zitadel < 4.17.1 affected
4.17.1 unaffected
< 3.4.15 affected
3.4.15 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105210

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
Source: CVE Program / CVE List V5
Vulnerability Description
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zitadel zitadel 0 ~ 4.17.1 -
zitadel zitadel 0 ~ 3.4.15 -

II. Public POCs for CVE-2026-105210

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105210

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105210 (2)

Same Patch Batch · zitadel · 2026-10-04 · 10 CVEs total

CVE-2026-105207 9.8 CRITICAL ZITADEL before 4.17.3 Account Takeover via External IdP Linking
CVE-2026-105209 9.6 CRITICAL ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollmen
CVE-2026-105215 9.1 CRITICAL ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
CVE-2026-105213 8.2 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE-2026-105211 8.1 HIGH ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
CVE-2026-105208 7.7 HIGH ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
CVE-2026-105212 7.5 HIGH ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
CVE-2026-105206 5.3 MEDIUM ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Servic
CVE-2026-105214 2.3 LOW Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification

IV. Related Vulnerabilities

V. Comments for CVE-2026-105210

No comments yet


Leave a comment