GHSA-cfjq-28r2-4jv5 · Severity: high · Ecosystem: go — Zitadel May Bypass Second Authentication Factor
Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a user has set up MFA without this requirement, Zitadel would consider single factor auhtenticated sessions as valid as well and not require multiple factors. Bypassing second authentication factors weakens multifactor authentication and enables attackers to bypass the more secure factor. An attacker can target the TOTP code alone, only six digits, bypassing password verification entirely and potentially compromising accounts with 2FA enabled. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18.
Conclusion & alert: CVE-2025-64103 is rated Moderate Risk (45.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.11%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-27 | 0.15% | 0.11% | -0.04% |
| 2 | 2026-02-28 | 0.09% | 0.15% | +0.06% |
| 3 | 2025-10-30 | — | 0.09% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-cfjq-28r2-4jv5 · Severity: high · Ecosystem: go — Zitadel May Bypass Second Authentication Factor
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| zitadel | zitadel | >= 2.53.6, <= 2.53.9 | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
| zitadel | zitadel | >= 2.54.3, <= 2.54.10 | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
| zitadel | zitadel | >= 2.55.0, < 2.71.18 | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
| zitadel | zitadel | >= 3.0.0, < 3.4.3 | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |
| zitadel | zitadel | >= 4.0.0, < 4.6.0 | cpe:2.3:a:zitadel:zitadel:*:*:*:*:*:*:*:* |