CVE-2026-105212

CVE-2026-105212 published: ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthen...

View full NVD advisory → ← Back to CVE watch