Description
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
Published: 2026-07-23
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Logto has a flaw that lets an attacker create an identity at a permissive identity provider using a victim’s email address. The system then links that new identity to the victim’s account without verifying the email, allowing the attacker to acquire the victim’s credentials and access privileges. This results in unauthorized access to the victim’s account and any resources or data associated with it.

Affected Systems

The vulnerability affects the Logto Logto platform. No specific product versions are listed in the CNA data, so any deployment of Logto that has not applied the subsequent fix may be susceptible.

Risk and Exploitability

The EPSS score is under 1%, but the CVSS score of 9.1 classifies this flaw as critical in severity. The EPSS score is under 1%, indicating a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits direct account takeover via SSO account linking, the potential impact is high for users lacking additional verification controls. No additional exploitation prerequisites are detailed in the advisory, but the attack path involves creating a new SSO identity and linking it to an existing Logto account using only an email address.

Generated by OpenCVE AI on August 3, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Logto release that enforces email verification before linking SSO identities
  • If a patch is unavailable, disable unverified SSO account linking in the Logto configuration until a fix is deployed
  • Audit current linked accounts for suspicious activities and revoke any that appear compromised
  • Set up monitoring on SSO linking logs to detect abnormal patterns promptly

Generated by OpenCVE AI on August 3, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Logto-io
Logto-io logto
Vendors & Products Logto-io
Logto-io logto

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
Title Unverified email-based SSO account linking
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-27T16:32:47.244Z

Reserved: 2026-07-13T16:09:08.015Z

Link: CVE-2026-15611

cve-icon Vulnrichment

Updated: 2026-07-27T16:31:37.719Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T16:17:13.947

Modified: 2026-07-27T17:16:34.800

Link: CVE-2026-15611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses