PT-2026-57292 · Logto+1 · Logto+1
CVE-2026-55789
·
Published
2026-07-10
·
Updated
2026-07-11
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Logto versions prior to 1.41.0
Description
The self-hosted SAML application IdP constructs signed SAML responses and assertions by substituting user-controlled profile attributes, such as name, email, and custom attribute-mapping values, into XML template placeholders using samlify 2.10.0. Because these placeholders are not escaped, an authenticated low-privilege user can inject XML markup into a profile attribute. This allows the attacker to force the system to sign forged SAML attributes, such as arbitrary roles, leading to privilege escalation and potential unauthorized administrative access or account takeover at relying Service Providers that authorize based on SAML attributes.
Recommendations
Update to version 1.41.0.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Logto
Samlify