CVE-2026-15614
Logto · Logto
Logto fails to invalidate IdP-initiated SAML sessions after use, enabling session replay attacks within the session validity window.
Executive summary
A critical authentication bypass vulnerability in Logto allows for the replay of SAML sessions, potentially enabling unauthorized account access.
Vulnerability
The application fails to properly delete IdP-initiated SAML sessions, resulting in an authentication bypass by capture-replay. This is an unauthenticated vulnerability that can be exploited by intercepting valid session data.
Business impact
This vulnerability carries a CVSS score of 7.5, reflecting its potential to grant attackers unauthorized access to user accounts. Such access could lead to significant data breaches, privilege escalation, and total compromise of user-related information within the Logto ecosystem.
Remediation
Immediate Action: Update the Logto installation to the latest version to ensure that SAML session invalidation is properly implemented.
Proactive Monitoring: Review authentication logs for anomalous session patterns or repeated SAML assertions that may indicate replay attempts.
Compensating Controls: Implement strict session timeout policies and utilize network-level monitoring to detect suspicious SAML traffic.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the potential for unauthorized account access, this update should be treated as a high priority. Organizations should upgrade to a patched version immediately to close the session replay window.