PT-2026-57282 · Logto · Logto

CVE-2026-55377

·

Published

2026-07-10

·

Updated

2026-07-12

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Logto versions prior to 1.41.0
Description The Account Center step-up check accepts any active verification record belonging to the current user where isVerified is set to true. An attacker with an existing Account API bearer token can create and verify a WebAuthn registration verification record for binding a new passkey. By sending this record in the logto-verification-id header, the Account Center routes treat the request as identityVerified=true. This allows the management of Multi-Factor Authentication (MFA) factors without requiring proof of possession of an existing password, identifier, or MFA factor.
Recommendations Update to version 1.41.0.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55377
GHSA-Q4H3-38GC-4P4J

Affected Products

Logto