Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens. | |
| Title | ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations | |
| First Time appeared |
Zitadel
Zitadel zitadel |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zitadel
Zitadel zitadel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-04T13:10:05.815Z
Reserved: 2026-10-04T13:02:21.188Z
Link: CVE-2026-105213
No data.
Status : Deferred
Published: 2026-10-04T15:16:32.687
Modified: 2026-10-04T15:16:32.800
Link: CVE-2026-105213
No data.
OpenCVE Enrichment
Updated: 2026-10-04T15:30:16Z
-
CWE-287
Improper Authentication