CVE-2026-105213 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE ID :CVE-2026-105213 Published : Oct. 4, 2026, 1:10 p.m. | 2 hours, 17 minutes ago Description :ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who...