PT-2026-97857 · Logto · Logto

CVE-2026-63203

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Logto versions 1.31.0 through 1.41.0
Description Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller with a same-user access token containing only the openid scope to retrieve stored social or enterprise SSO provider access tokens. This occurs because the handlers authenticate the user but fail to require the identities scope, which is intended to protect identity-detail operations, thereby bypassing the Account API consent boundary. This issue can be exploited if federated token-set storage is enabled and the user has authenticated via a supported connector, allowing a low-trust application to use the disclosed provider token against upstream APIs. The affected endpoints are 'GET /api/my-account/identities/{target}/access-token' and 'GET /api/my-account/sso-identities/{connectorId}/access-token'.
Recommendations Update to version 1.42.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63203
GHSA-6G9Q-QRX7-3JXF

Affected Products

Logto