PT-2026-83286 · Logto · Logto

·

CVE-2026-82263

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Logto versions prior to 1.42.1
Description A server-side request forgery (SSRF) issue exists in the OIDC SSO connector creation endpoint. The system fails to validate the issuer URL parameter, allowing tenant administrators with Management API credentials to provide arbitrary internal URLs. This can trigger HTTP GET requests to private network services, with the resulting response content returned in the API responses.
Recommendations Update to a version newer than 1.42.0. Restrict access to the OIDC SSO connector creation endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82263

Affected Products

Logto