{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azitadellogin_v2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zitadel:login_v2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-85056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ZITADEL Login V2 (4.0.0-4.16.0)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","mfa-bypass","cve-2026-85056"],"_cs_type":"advisory","_cs_vendors":["ZITADEL"],"content_html":"\u003cp\u003eZITADEL's Login V2 UI contains a vulnerability, tracked as CVE-2026-85056, that permits an authentication bypass for users who have enrolled in multi-factor authentication (MFA) but are not subject to mandatory 'Force MFA' policies. The issue arises from the way the Login V2 UI handles browser sessions: it issues a session token immediately upon successful password verification, before the secondary authentication factor is satisfied. If a user or an attacker triggers the login process, completes password authentication, and then abandons the MFA prompt, the resulting session remains partially authenticated. By restarting the login flow, the system incorrectly reuses the existing password-verified session to finalize the authentication to OIDC or SAML-integrated applications, bypassing the requirement for the second factor.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is limited to the hosted Login V2 interface and does not impact internal ZITADEL console access or administration APIs. It specifically affects ZITADEL versions 4.0.0 through 4.16.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker possessing valid user credentials (such as via phishing or credential stuffing) to gain unauthorized access to target applications protected by ZITADEL. Because this bypass effectively negates the security provided by TOTP, OTP, or U2F, it significantly increases the risk of account takeover. Organizations that do not have 'Force MFA' policies enabled for all users are at risk, as the system fails to treat voluntarily enrolled MFA as a mandatory barrier during the session reuse event.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and identity teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade ZITADEL installations to version 4.16.1 or later immediately to address the underlying session logic vulnerability.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, modify the organization's login policy to enable 'Force MFA' or 'Force MFA for local users only'. This mitigates the risk by making second-factor verification mandatory for all relevant authentication requests, effectively closing the bypass vector.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected OIDC/SAML callback completions where MFA verification events are absent despite MFA enrollment for the user account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:07:58Z","date_published":"2026-09-24T20:07:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-mfa-bypass/","summary":"A session-reuse vulnerability in ZITADEL Login V2 (CVE-2026-85056) allows attackers with valid credentials to bypass MFA by abandoning and restarting the login flow in organizations where MFA is not strictly enforced.","title":"ZITADEL Login V2 MFA Bypass via Session Reuse","url":"https://feed.craftedsignal.io/briefs/2026-09-zitadel-mfa-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zitadel:login_v2:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}