Vulnerability Description
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/
- https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/
FAQ
What is CVE-2026-15611?
CVE-2026-15611 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
How severe is CVE-2026-15611?
CVE-2026-15611 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-15611?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.