PT-2026-64016 · Logto · Logto

CVE-2026-15611

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Logto (affected versions not specified)
Description Logto allows unverified email-based SSO account linking. When a new SSO login occurs for an unknown (issuer, identityId) pair, the system searches for a local user by the email provided by the Identity Provider (IdP) and links the SSO identity to that account without requiring the IdP to confirm the email verified status. This flaw enables an attacker to register an identity at a permissive IdP using a victim's email to gain unauthorized access to the victim's account. Additionally, other issues in the identity-processing pipeline allow for MFA bypass, SSO replay, and the acceptance of identity assertions without proper cryptographic or validity checks.
Recommendations Apply vendor-supplied patches. Review identity provider configurations to ensure robust email verification and assertion validation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15611

Affected Products

Logto