What is CVE-2026-15616?
CVE-2026-15616 is a vulnerability in Logto where locally configured MFA is not enforced during SSO authentication, allowing users to bypass second-factor requirements and gain unauthorized access. Organizations should immediately update Logto to the latest version and verify configurations to enforce MFA in the SSO flow.
Azərbaycanca: CVE-2026-15616, Logto platformasında SSO autentifikasiyası zamanı lokal olaraq konfiqurasiya edilmiş MFA-nın tətbiq edilməməsi zəifliyidir. Bu, istifadəçilərə ikinci faktor tələbini keçərək icazəsiz giriş əldə etməyə imkan verir. Təşkilatlar dərhal Logto-nu ən son versiyaya yeniləməli və SSO axınında MFA tətbiqini məcburi etmək üçün konfiqurasiyaları yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What security mechanism does CVE-2026-15616 bypass in the Logto platform?
CVE-2026-15616 causes locally configured MFA to not be enforced during SSO authentication in Logto, allowing users to bypass second-factor requirements.
What measures should organizations take to mitigate CVE-2026-15616?
Organizations should immediately update Logto to the latest version and verify configurations to enforce MFA in the SSO flow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.