What is CVE-2026-15612?
CVE-2026-15612 is a vulnerability in Logto that bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens. Affected users should apply the patch provided by Logto immediately.
Azərbaycanca: CVE-2026-15612, Logto sistemində OIDC nonce yoxlamasının id_token içində nonce claim olmadıqda keçilməsinə imkan verən boşluqdur. Bu, autentifikasiya tokenlərinin təkrar istifadəsinə (replay attack) səbəb ola bilər. Təsirə məruz qalan istifadəçilər Logto tərəfindən buraxılmış yeniləməni tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
What risk does CVE-2026-15612 pose in Logto?
This vulnerability allows the OIDC nonce validation to be bypassed when the nonce claim is absent from the id_token, which can lead to replay attacks of authentication tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.