ZITADEL: MFA bypass via session reuse in Login V2
Published Sep 24, 2026
8.2
HIGHCVSS 3.1
EPSS 0.29%
Description
ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization enables Force MFA or Force MFA for local users only, so a voluntarily enrolled factor can be skipped while completing an OIDC or SAML callback for a customer application. Login V1, the ZITADEL Console, Management and Admin APIs, and user self-management are not affected. This issue is fixed in version 4.16.1.
Affected products
-
- Version >= 4.0.0, < 4.16.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/zitadel/zitadel
Go
Introduced 0 Fixed 1.80.0-v2.20.0.20260717062356-56f4798ed31f
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/zitadel/zitadel | 0 | 1.80.0-v2.20.0.20260717062356-56f4798ed31f |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (5)
- https://github.com/advisories/GHSA-9993-rfwp-rhwf Advisory
- https://github.com/zitadel/zitadel/commit/049dbb25a56587fb3980c85c99819cad69f637db x_refsource_MISC
- https://github.com/zitadel/zitadel/commit/56f4798ed31fc1cfcd9a0e7f6f0152289d2fdc43 x_refsource_MISC
- https://github.com/zitadel/zitadel/releases/tag/v4.16.1 x_refsource_MISC
- https://github.com/zitadel/zitadel/security/advisories/GHSA-9993-rfwp-rhwf x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-9993-rfwp-rhwf | Advisory | |
| https://github.com/zitadel/zitadel/commit/049dbb25a56587fb3980c85c99819cad69f637db | x_refsource_MISC | |
| https://github.com/zitadel/zitadel/commit/56f4798ed31fc1cfcd9a0e7f6f0152289d2fdc43 | x_refsource_MISC | |
| https://github.com/zitadel/zitadel/releases/tag/v4.16.1 | x_refsource_MISC | |
| https://github.com/zitadel/zitadel/security/advisories/GHSA-9993-rfwp-rhwf | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.