Logto vulnerabilities
4 CVEs tracked
Logto appears in our reporting with critical authentication vulnerabilities. The main themes center around a lack of email verification in SSO account linking (CVE-2026-15611) and issues in SAML session management, which can lead to unauthorized access. In this context, defenders should pay attention to the risk of identifier manipulation due to CVE-2026-15617 (principal collision from lack of normalization), and dangers of session replay from CVE-2026-15614 (silent failure to delete SAML sessions) and CVE-2026-15615 (unvalidated SAML Conditions element).
Azərbaycanca: Logto hesabatlarımızda kritik autentifikasiya zəiflikləri ilə əlaqəli görünür. Əsas hadisələr e-poçt əsaslı SSO hesab əlaqələndirməsində doğrulama çatışmazlığı (CVE-2026-15611) və SAML seans idarəetməsindəki problemlər ətrafında cəmlənir ki, bu da icazəsiz girişə səbəb ola bilər. Bu kontekstdə, müdafiəçilər CVE-2026-15617 (principal lookup-da normalizasiya çatışmazlığı səbəbindən toqquşma) səbəbindən identifikator manipulyasiyası riskinə, eləcə də CVE-2026-15614 (SAML seanslarının səssiz şəkildə silinməməsi) və CVE-2026-15615 (SAML Conditions elementinin validasiya olunmaması) nəticəsində yaranan seans təkrarı təhlükələrinə diqqət yetirməlidir.
This vendor's CVEs4
This hub is built from skopnix's own reporting on Logto: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.