Description
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
Published: 2026-07-23
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exists because Logto does not enforce the locally configured multi‑factor authentication (MFA) during single sign‑on (SSO) authentication workflows. The result is that users who normally must provide a second factor are able to sign in using only their password, thereby gaining full access to the application without meeting the intended security checks. This issue directly reduces the integrity of the authentication process and allows an attacker who compromises a user’s primary credentials to bypass all additional security controls.

Affected Systems

The flaw affects installations of Logto, specifically instances that rely on locally configured MFA settings. No specific product version is listed, so any deployed Logto environment that has MFA enabled but does not enforce it during SSO can be impacted.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low probability of widespread exploitation at present, and the vulnerability is not yet listed in the CISA KEV catalog. However, because the flaw allows full bypass of MFA, the potential impact is high; an attacker only needs valid primary credentials to compromise a user account. The likely attack vector is through normal SSO login flows that the Logto platform facilitates for end users. No additional exploitation conditions are stated beyond the misconfiguration of MFA enforcement.

Generated by OpenCVE AI on August 2, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Logto patch that enforces MFA during SSO sign‑in.
  • Enable the MFA enforcement setting for all SSO connections via the Logto administrative console.
  • Restrict SSO traffic to internal networks or enforce VPN usage for external access.
  • Continuously monitor authentication logs for SSO attempts that do not include second‑factor validation.

Generated by OpenCVE AI on August 2, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Logto-io
Logto-io logto
Vendors & Products Logto-io
Logto-io logto

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-308
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
Title Local MFA not enforced during SSO sign-in
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-27T15:28:21.318Z

Reserved: 2026-07-13T16:14:31.396Z

Link: CVE-2026-15616

cve-icon Vulnrichment

Updated: 2026-07-27T15:27:24.316Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T16:17:14.330

Modified: 2026-07-27T16:17:02.897

Link: CVE-2026-15616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T15:45:03Z

Weaknesses
  • CWE-308

    Use of Single-factor Authentication