CVE-2025-64103 - CVE House
Back to Database
Status published High CVE-2025-64103

Zitadel Bypass Second Authentication Factor

Vulnerability Description

Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a user has set up MFA without this requirement, Zitadel would consider single factor auhtenticated sessions as valid as well and not require multiple factors. Bypassing second authentication factors weakens multifactor authentication and enables attackers to bypass the more secure factor. An attacker can target the TOTP code alone, only six digits, bypassing password verification entirely and potentially compromising accounts with 2FA enabled. This vulnerability is fixed in 4.6.0, 3.4.3, and 2.71.18.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64103

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

zitadel
Vulnerable Versions:
>= 4.0.0-rc.1, < 4.6.0, >= 3.0.0-rc.1, < 3.4.3, >= 2.55.0, < 2.71.18, >= 2.54.3, <= 2.54.10, >= 2.53.6, <= 2.53.9

Timeline

Official Publish: October 29th, 2025
Last Modified: October 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)