Session Replay Vulnerability in Logto by Logto.io
CVE-2026-15614

Currently unrated

Key Information:

Vendor

Logto

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-15614?

Logto has a vulnerability that permits the silent failure to delete IdP-initiated SAML sessions. This flaw can lead to unauthorized session replay and reuse, remaining active within the session’s validity period. Attackers can exploit this vulnerability to hijack user sessions, posing significant risks to application integrity and user data security.

Affected Version(s)

Logto 1.21.0 <= 1.37.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.