CVE-2026-15614

Logto · Logto

Logto fails to invalidate IdP-initiated SAML sessions after use, enabling session replay attacks within the session validity window.

Executive summary

A critical authentication bypass vulnerability in Logto allows for the replay of SAML sessions, potentially enabling unauthorized account access.

Vulnerability

The application fails to properly delete IdP-initiated SAML sessions, resulting in an authentication bypass by capture-replay. This is an unauthenticated vulnerability that can be exploited by intercepting valid session data.

Business impact

This vulnerability carries a CVSS score of 7.5, reflecting its potential to grant attackers unauthorized access to user accounts. Such access could lead to significant data breaches, privilege escalation, and total compromise of user-related information within the Logto ecosystem.

Remediation

Immediate Action: Update the Logto installation to the latest version to ensure that SAML session invalidation is properly implemented.

Proactive Monitoring: Review authentication logs for anomalous session patterns or repeated SAML assertions that may indicate replay attempts.

Compensating Controls: Implement strict session timeout policies and utilize network-level monitoring to detect suspicious SAML traffic.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the potential for unauthorized account access, this update should be treated as a high priority. Organizations should upgrade to a patched version immediately to close the session replay window.