Impact
This vulnerability exists because Logto does not enforce the locally configured multi‑factor authentication (MFA) during single sign‑on (SSO) authentication workflows. The result is that users who normally must provide a second factor are able to sign in using only their password, thereby gaining full access to the application without meeting the intended security checks. This issue directly reduces the integrity of the authentication process and allows an attacker who compromises a user’s primary credentials to bypass all additional security controls.
Affected Systems
The flaw affects installations of Logto, specifically instances that rely on locally configured MFA settings. No specific product version is listed, so any deployed Logto environment that has MFA enabled but does not enforce it during SSO can be impacted.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating a very low probability of widespread exploitation at present, and the vulnerability is not yet listed in the CISA KEV catalog. However, because the flaw allows full bypass of MFA, the potential impact is high; an attacker only needs valid primary credentials to compromise a user account. The likely attack vector is through normal SSO login flows that the Logto platform facilitates for end users. No additional exploitation conditions are stated beyond the misconfiguration of MFA enforcement.
OpenCVE Enrichment