PT-2026-64016 · Logto · Logto
CVE-2026-15611
·
Published
2026-07-23
·
Updated
2026-07-23
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Logto (affected versions not specified)
Description
Logto allows unverified email-based SSO account linking. When a new SSO login occurs for an unknown
(issuer, identityId) pair, the system searches for a local user by the email provided by the Identity Provider (IdP) and links the SSO identity to that account without requiring the IdP to confirm the email verified status. This flaw enables an attacker to register an identity at a permissive IdP using a victim's email to gain unauthorized access to the victim's account. Additionally, other issues in the identity-processing pipeline allow for MFA bypass, SSO replay, and the acceptance of identity assertions without proper cryptographic or validity checks.Recommendations
Apply vendor-supplied patches.
Review identity provider configurations to ensure robust email verification and assertion validation.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Logto