Principal Lookup Vulnerability in Logto by Logto.io
CVE-2026-15617
Currently unrated
What is CVE-2026-15617?
Logto is vulnerable due to improper normalization of email and identifier strings during principal lookup. This can lead to principal collision, allowing unauthorized access to user accounts through case- or Unicode-distinguished identities. Users may unknowingly gain access to accounts that are not their own, posing significant security risks if left unaddressed.
Affected Version(s)
Logto 1.10.1 <= 1.37.1
