CVE-2026-15616
Logto does not enforce locally configured multi‑factor authentication (MFA) during single sign‑on (SSO) authentication. This flaw lets attackers bypass the second‑factor requirement and gain unauthorized access to user accounts. The vulnerability is critical because it can be exploited remotely without any user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Logto, a single sign‑on platform. The issue affects any organization that has enabled MFA in Logto but relies on SSO for authentication.
Real-world impact
An attacker can log in as a legitimate user without providing the second‑factor code, potentially accessing sensitive data, administrative functions, or other protected resources.
Why this severity
The CVSS score of 9.1 reflects a network‑based attack that requires no privileges or user interaction, has low complexity, and grants full confidentiality and integrity compromise. The lack of any mitigations on the client side makes the impact severe.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 23, 2026 · 9d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.