CVE-2026-105210 - ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
CVE ID :CVE-2026-105210 Published : Oct. 4, 2026, 1:10 p.m. | 2 hours, 17 minutes ago Description :ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an...