What is CVE-2026-15617?
CVE-2026-15617 is a vulnerability in Logto where principal lookup fails to normalize email and identifier strings. This allows principal collision, enabling unauthorized account access by using case-variant or Unicode-different identities. Updating Logto to the latest version is recommended.
Azərbaycanca: CVE-2026-15617, Logto platformasında e-poçt və identifikator sətirlərinin normallaşdırılmaması səbəbindən baş verən boşluqdur. Bu, principal collision yaradaraq, fərqli hərf ölçüsü və ya Unicode simvolları ilə eyni hesabın qeydiyyatını mümkün edir və nəticədə icazəsiz girişə yol aça bilər. Təsirə məruz qalan sistemlərdə Logto-nun ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Logto
FAQ1
What is the primary issue caused by CVE-2026-15617 in Logto?
A principal collision occurs because email and identifier strings are not normalized. This allows unauthorized account access by registering the same account using case-variant or Unicode-different identities.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.