Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9993-rfwp-rhwf | ZITADEL: MFA bypass via session reuse in Login V2 |
Thu, 24 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization enables Force MFA or Force MFA for local users only, so a voluntarily enrolled factor can be skipped while completing an OIDC or SAML callback for a customer application. Login V1, the ZITADEL Console, Management and Admin APIs, and user self-management are not affected. This issue is fixed in version 4.16.1. | |
| Title | ZITADEL: MFA bypass via session reuse in Login V2 | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-24T17:34:13.328Z
Reserved: 2026-09-02T21:21:01.774Z
Link: CVE-2026-85056
No data.
Status : Deferred
Published: 2026-09-24T18:19:04.040
Modified: 2026-09-24T18:19:04.180
Link: CVE-2026-85056
No data.
OpenCVE Enrichment
No data.
-
CWE-287
Improper Authentication
Github GHSA