OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-85056

HIGH · CVSS 8.2 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

ZITADEL versions 4.0.0 to 4.16.1 are vulnerable due to a flaw in the Login V2 component, which allows session reuse after password verification without requiring a second factor of authentication, potentially bypassing multi-factor authentication (MFA) for subsequent login attempts. This vulnerability could lead to unauthorized access to user accounts if MFA is not enforced by the organization. Organizations using ZITADEL for identity management, especially those relying on MFA for security, should prioritize upgrading to version 4.16.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85056
Severity
HIGH
CVSS
8.2
EPSS
0.29%

Original NVD Description

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a user's enrolled TOTP, OTP, or U2F second factor. When the MFA step is abandoned and login starts again, session-validity checks require MFA only when the organization enables Force MFA or Force MFA for local users only, so a voluntarily enrolled factor can be skipped while completing an OIDC or SAML callback for a customer application. Login V1, the ZITADEL Console, Management and Admin APIs, and user self-management are not affected. This issue is fixed in version 4.16.1.