<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-85056 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-85056/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 20:07:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-85056/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>ZITADEL Login V2 MFA Bypass via Session Reuse</title><link>https://feed.craftedsignal.io/briefs/2026-09-zitadel-mfa-bypass/</link><pubDate>Thu, 24 Sep 2026 20:07:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zitadel-mfa-bypass/</guid><description>A session-reuse vulnerability in ZITADEL Login V2 (CVE-2026-85056) allows attackers with valid credentials to bypass MFA by abandoning and restarting the login flow in organizations where MFA is not strictly enforced.</description><content:encoded><![CDATA[<p>ZITADEL's Login V2 UI contains a vulnerability, tracked as CVE-2026-85056, that permits an authentication bypass for users who have enrolled in multi-factor authentication (MFA) but are not subject to mandatory 'Force MFA' policies. The issue arises from the way the Login V2 UI handles browser sessions: it issues a session token immediately upon successful password verification, before the secondary authentication factor is satisfied. If a user or an attacker triggers the login process, completes password authentication, and then abandons the MFA prompt, the resulting session remains partially authenticated. By restarting the login flow, the system incorrectly reuses the existing password-verified session to finalize the authentication to OIDC or SAML-integrated applications, bypassing the requirement for the second factor.</p>
<p>The vulnerability is limited to the hosted Login V2 interface and does not impact internal ZITADEL console access or administration APIs. It specifically affects ZITADEL versions 4.0.0 through 4.16.0.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker possessing valid user credentials (such as via phishing or credential stuffing) to gain unauthorized access to target applications protected by ZITADEL. Because this bypass effectively negates the security provided by TOTP, OTP, or U2F, it significantly increases the risk of account takeover. Organizations that do not have 'Force MFA' policies enabled for all users are at risk, as the system fails to treat voluntarily enrolled MFA as a mandatory barrier during the session reuse event.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and identity teams:</p>
<ul>
<li>Upgrade ZITADEL installations to version 4.16.1 or later immediately to address the underlying session logic vulnerability.</li>
<li>If immediate patching is not possible, modify the organization's login policy to enable 'Force MFA' or 'Force MFA for local users only'. This mitigates the risk by making second-factor verification mandatory for all relevant authentication requests, effectively closing the bypass vector.</li>
<li>Audit logs for unexpected OIDC/SAML callback completions where MFA verification events are absent despite MFA enrollment for the user account.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>mfa-bypass</category><category>cve-2026-85056</category></item></channel></rss>