What is CVE-2026-15611?
CVE-2026-15611 is a vulnerability in Logto where unverified email-based SSO account linking allows an attacker to register an identity at a permissive IdP using a victim's email, gaining unauthorized access to the victim's account. Affected systems should enforce mandatory email verification for all SSO account linking processes.
Azərbaycanca: CVE-2026-15611 Logto platformasında təsdiqlənməmiş email əsaslı SSO hesab əlaqələndirmə zəifliyidir. Təcavüzkar, qurbanın email ünvanından istifadə edərək icazə verilən IdP-də şəxsiyyət qeydiyyatdan keçirə və hədəf hesaba icazəsiz giriş əldə edə bilər. Dərhal Logto konfiqurasiyasında email doğrulamasını məcburi edin.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Logto
FAQ2
Through which mechanism does CVE-2026-15611 allow unauthorized access in the Logto platform?
The vulnerability occurs through unverified email-based SSO account linking. An attacker can register an identity at a permissive IdP using the victim's email and gain unauthorized access to the target account.
What immediate mitigation should be applied to protect against CVE-2026-15611?
Enforce mandatory email verification in the Logto configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.