Unverified Email-Based SSO Account Linking in Logto by Logto
CVE-2026-15611
Currently unrated
What is CVE-2026-15611?
Logto contains a security flaw that permits unverified email-based Single Sign-On (SSO) account linking. This vulnerability allows an attacker to exploit a permissive Identity Provider (IdP) by registering an identity using an unsuspecting victim's email address. Consequently, the attacker can gain unauthorized access to the victim’s account, compromising sensitive information and user privacy. It is crucial for users of Logto to ensure they are using the latest versions to mitigate this risk.
Affected Version(s)
Logto 1.11.0 <= 1.37.1
