CVE-2026-105213

CVE-2026-105213 published: ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token ca...

View full NVD advisory → ← Back to CVE watch