CVE-2026-105210

CVE-2026-105210 published: ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers kno...

View full NVD advisory → ← Back to CVE watch