SAML Element Validation Flaw in Logto Affects Security
CVE-2026-15615
Currently unrated
What is CVE-2026-15615?
A vulnerability in Logto's SSO implementation allows attackers to exploit insufficient validation of the SAML element. This flaw permits the omission of critical time and audience restrictions, enabling the potential for assertion replay attacks, where malicious entities may leverage these assertions indefinitely without proper validation. This can seriously compromise the security of authentication processes and user data.
Affected Version(s)
Logto 1.12.0 <= 1.37.1
