CVE-2025-64103 is a critical authentication bypass vulnerability affecting Zitadel versions starting from 2.53.6, 2.54.3, and 2.55.0. It allowed single-factor authenticated sessions to be considered valid even when a user had configured multi-factor authentication (MFA), provided the login policy didn't explicitly require MFA. This flaw, rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), enables attackers to bypass the more secure MFA factor, potentially compromising accounts by targeting only the TOTP code. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability is severe due to its ease of exploitation and complete compromise potential. Patches are available in versions 4.6.0, 3.4.3, and 2.71.18.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.53.6, <= 2.53.9CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 2.54.3, <= 2.54.10CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 2.55.0, < 2.71.18CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.4.3CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.6.0CPE matchmatch criteria | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.