OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105213 (CVSS 8.8)

NVD · officialPublished Oct 4, 2026Risk 37/100

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source