What is CVE-2026-15614?
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. This vulnerability could allow unauthorized access even after user logout. Session management should be improved on affected systems.
Azərbaycanca: Logto sistemində İdP tərəfindən başladılan SAML sessiyalarının silinməsi səssizcə uğursuz olur, bu da sessiyanın yenidən istifadəsi və təkrar oynadılmasına imkan yaradır. Bu zəiflik istifadəçi çıxış etdikdən sonra belə icazəsiz girişə səbəb ola bilər. Təsirə məruz qalan sistemlərdə sessiya idarəetməsi təkmilləşdirilməlidir.
Related CVEs
link basis: shared vendor: Logto
FAQ2
What risk does CVE-2026-15614 pose in Logto?
This vulnerability could allow unauthorized access even after user logout by enabling replay and reuse of IdP-initiated SAML sessions.
What is the root cause of CVE-2026-15614?
The root cause is that Logto silently fails to delete IdP-initiated SAML sessions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.