Known Vulnerabilities for Logto by Logto-io
Listed below are 10 of the newest known vulnerabilities associated with "Logto" by "Logto-io".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55789 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML applicat... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55377 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up ch... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55370 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verificatio... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54714 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML Re... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-15617 json | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthoriz... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-15616 json | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements ... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-15615 json | Logto omits validation of the SAML |
Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-15614 json | Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-15612 json | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication toke... | Not Provided | 2026-07-23 | 2026-07-27 |
| CVE-2026-15611 json | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP usi... | Not Provided | 2026-07-23 | 2026-07-27 |