Impact
Prior to version 1.41.0, Logto’s Account Center step‑up logic accepted any active verification record with isVerified set to true, regardless of which MFA factor it represented. An attacker can create a WebAuthn registration verification record using a legitimate Account API bearer token, then send it via the logto-verification‑id header. The Account Center treats the record as identityVerified=true, allowing the attacker to add or manage MFA factors without proving possession of an existing password, identifier, or MFA factor. This flaw, classified as CWE‑287, permits authentication bypass and unauthorized manipulation of MFA settings.
Affected Systems
This vulnerability affects all releases of the logto-io:logto product prior to version 1.41.0. Any user maintaining an earlier release is susceptible until they upgrade to or above the fixed version.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. Exploitation requires a valid Account API bearer token, which could be obtained through credential compromise or insider access; thus the likely attack vector is token theft or reuse. The EPSS score of less than 1% suggests a low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV, indicating no confirmed live exploitation to date.
OpenCVE Enrichment