What is CVE-2026-15615?
CVE-2026-15615: A vulnerability in Logto where the SAML <Conditions> element is not validated. This allows attackers to strip time and audience restrictions, enabling indefinite replay of assertions. Logto users should immediately apply updates and review their SAML configurations.
Azərbaycanca: CVE-2026-15615: Logto sistemində SAML <Conditions> elementinin yoxlanılmaması zəifliyi aşkar edilib. Bu, təcavüzkarlara vaxt və auditoriya məhdudiyyətlərini aradan qaldıraraq təsdiq məlumatlarını məhdudiyyətsiz təkrar istifadə etməyə imkan verir. Logto istifadəçiləri dərhal yeniləmə tətbiq etməli və SAML konfiqurasiyalarını nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ1
What threat does CVE-2026-15615 pose to Logto users?
This vulnerability allows attackers to strip time and audience restrictions in Logto by exploiting the lack of validation of the SAML <Conditions> element. As a result, assertions can be replayed indefinitely.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.