PT-2026-64017 · Logto · Logto

CVE-2026-15612

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Logto (affected versions not specified)
Description Logto fails to properly validate the OIDC nonce when the nonce claim is missing from the id token. This flaw allows for the replay of authentication tokens and weakens session-binding. OIDC (OpenID Connect) is an identity layer on top of the OAuth 2.0 protocol, and a nonce is a unique string used to prevent replay attacks by ensuring that a token is used only once.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15612

Affected Products

Logto