SAML Element Validation Flaw in Logto Affects Security
CVE-2026-15615

Currently unrated

Key Information:

Vendor

Logto

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-15615?

A vulnerability in Logto's SSO implementation allows attackers to exploit insufficient validation of the SAML element. This flaw permits the omission of critical time and audience restrictions, enabling the potential for assertion replay attacks, where malicious entities may leverage these assertions indefinitely without proper validation. This can seriously compromise the security of authentication processes and user data.

Affected Version(s)

Logto 1.12.0 <= 1.37.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.