Principal Lookup Vulnerability in Logto by Logto.io
CVE-2026-15617

Currently unrated

Key Information:

Vendor

Logto

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-15617?

Logto is vulnerable due to improper normalization of email and identifier strings during principal lookup. This can lead to principal collision, allowing unauthorized access to user accounts through case- or Unicode-distinguished identities. Users may unknowingly gain access to accounts that are not their own, posing significant security risks if left unaddressed.

Affected Version(s)

Logto 1.10.1 <= 1.37.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.