Impact
Logto has a flaw that lets an attacker create an identity at a permissive identity provider using a victim’s email address. The system then links that new identity to the victim’s account without verifying the email, allowing the attacker to acquire the victim’s credentials and access privileges. This results in unauthorized access to the victim’s account and any resources or data associated with it.
Affected Systems
The vulnerability affects the Logto Logto platform. No specific product versions are listed in the CNA data, so any deployment of Logto that has not applied the subsequent fix may be susceptible.
Risk and Exploitability
The EPSS score is under 1%, but the CVSS score of 9.1 classifies this flaw as critical in severity. The EPSS score is under 1%, indicating a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits direct account takeover via SSO account linking, the potential impact is high for users lacking additional verification controls. No additional exploitation prerequisites are detailed in the advisory, but the attack path involves creating a new SSO identity and linking it to an existing Logto account using only an email address.
OpenCVE Enrichment