Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15617 | 1 Logto-io | 1 Logto | 2026-08-01 | 9.1 Critical |
| Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. | ||||
| CVE-2026-15616 | 1 Logto-io | 1 Logto | 2026-08-01 | 9.1 Critical |
| Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. | ||||
| CVE-2026-15612 | 1 Logto-io | 1 Logto | 2026-08-01 | 9.1 Critical |
| Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. | ||||
| CVE-2026-15614 | 1 Logto-io | 1 Logto | 2026-07-28 | 7.5 High |
| Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. | ||||
Page 1 of 1.