Session Replay Vulnerability in Logto by Logto.io
CVE-2026-15614
Currently unrated
What is CVE-2026-15614?
Logto has a vulnerability that permits the silent failure to delete IdP-initiated SAML sessions. This flaw can lead to unauthorized session replay and reuse, remaining active within the session’s validity period. Attackers can exploit this vulnerability to hijack user sessions, posing significant risks to application integrity and user data security.
Affected Version(s)
Logto 1.21.0 <= 1.37.1
