CVE-2026-105212: high-severity vulnerability in zitadel
ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
zitadel · zitadelRelated CVEs — zitadel
In the same product, most dangerous first.
CVE-2024-49757HIGHZitadel User Registration Bypass VulnerabilityEPSS 2.5%CVE-2022-36051HIGHBroken Authorization in ZITADEL ActionsEPSS 1.0%CVE-2024-28855HIGHZITADEL vulnerable to improper HTML sanitizationEPSS 0.8%CVE-2024-29892MEDIUMZITADEL's actions can overload reserved claimsEPSS 0.8%CVE-2023-49097HIGHZITADEL vulnerable account takeover via malicious host header injectionEPSS 0.8%CVE-2024-29891HIGHZITADEL Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP BypassEPSS 0.8%