CVE-2026-105213 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
Brief
CVE ID : CVE-2026-105213
Published : Oct. 4, 2026, 3:16 p. m.
- 4 hours, 15 minutes ago
Description : ZITADEL 4. x before 4.
- 1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
