Multi-Factor Authentication Bypass in Logto Product by Logto
CVE-2026-15616

Currently unrated

Key Information:

Vendor

Logto

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-15616?

Logto's implementation of Multi-Factor Authentication (MFA) during Single Sign-On (SSO) authentication processes is flawed. The system fails to enforce locally configured MFA settings, which can inadvertently allow users to bypass the second-factor authentication requirement. This oversight enables unauthorized access to potentially sensitive user accounts, posing significant security risks for organizations utilizing Logto for their authentication solutions.

Affected Version(s)

Logto 1.19.0 <= 1.37.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.