PatchSiren cyber security CVE debrief
CVE-2026-56739 logto-io CVE debrief
CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. Prior to version 1.43.0, Logto's webhook delivery and custom OAuth2 and OIDC connectors can be exploited to reach special-use and cloud metadata addresses, potentially exposing internal data or upstream provider credentials. This issue requires tenant administrative configuration access but can cross the server's network boundary.
- Vendor
- logto-io
- Product
- logto
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-24
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-24
- Advisory updated
- 2026-09-28
Who should care
Defenders responsible for Logto deployments, especially those with custom OAuth2 or OIDC connectors, should assess exposure and prioritize upgrading to version 1.43.0 or later. Monitoring for unusual network activity and reviewing webhook delivery configurations are also recommended.
Why it matters
CVE-2026-56739 is a high-severity vulnerability in Logto that can lead to data exposure. Defenders should verify exposure, prioritize upgrading to version 1.43.0 or later, and monitor for unusual network activity.
- Verify exposure in Logto deployments with custom OAuth2 or OIDC connectors.
- Upgrade to version 1.43.0 or later to prevent potential data exposure.
- Monitor for unusual network activity related to webhook delivery.
- Review webhook delivery configurations for potential security risks.
Technical summary
CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. The issue arises from Logto's webhook delivery and custom OAuth2 and OIDC connectors, which can be exploited to reach special-use and cloud metadata addresses. This can potentially expose internal data or upstream provider credentials. The vulnerability requires tenant administrative configuration access but can cross the server's network boundary. The issue is fixed in version 1.43.0.
Defensive priority
Defenders should prioritize verifying exposure in Logto deployments, especially those with custom OAuth2 or OIDC connectors, and upgrade to version 1.43.0 or later. Monitoring for unusual network activity and reviewing webhook delivery configurations are also recommended.
Recommended defensive actions
- Verify if Logto deployments are using custom OAuth2 or OIDC connectors and assess exposure.
- Upgrade Logto to version 1.43.0 or later.
- Monitor for unusual network activity related to webhook delivery.
- Review webhook delivery configurations for potential security risks.
- Perform an inventory of assets using Logto for authentication.
- Establish a rollback plan in case issues arise during the upgrade.
- Track the status of the CVE-2026-56739 remediation efforts.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. GitHub references offer additional context on the fix in version 1.43.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56739 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56739
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56739 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56739
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/logto-io/logto/commit/16f4b2e732d5114ac98646c9370ec6ab61d6ed26
-
Source reference
Unverified legacy reference
URL: https://github.com/logto-io/logto/pull/9501
-
Source reference
Unverified legacy reference
URL: https://github.com/logto-io/logto/releases/tag/v1.43.0
-
Source reference
Unverified legacy reference
URL: https://github.com/logto-io/logto/security/advisories/GHSA-3556-624q-c5w3
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.