PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56739 logto-io CVE debrief

CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. Prior to version 1.43.0, Logto's webhook delivery and custom OAuth2 and OIDC connectors can be exploited to reach special-use and cloud metadata addresses, potentially exposing internal data or upstream provider credentials. This issue requires tenant administrative configuration access but can cross the server's network boundary.

Vendor
logto-io
Product
logto
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-28
Advisory published
2026-09-24
Advisory updated
2026-09-28

Who should care

Defenders responsible for Logto deployments, especially those with custom OAuth2 or OIDC connectors, should assess exposure and prioritize upgrading to version 1.43.0 or later. Monitoring for unusual network activity and reviewing webhook delivery configurations are also recommended.

Why it matters

CVE-2026-56739 is a high-severity vulnerability in Logto that can lead to data exposure. Defenders should verify exposure, prioritize upgrading to version 1.43.0 or later, and monitor for unusual network activity.

  • Verify exposure in Logto deployments with custom OAuth2 or OIDC connectors.
  • Upgrade to version 1.43.0 or later to prevent potential data exposure.
  • Monitor for unusual network activity related to webhook delivery.
  • Review webhook delivery configurations for potential security risks.

Technical summary

CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. The issue arises from Logto's webhook delivery and custom OAuth2 and OIDC connectors, which can be exploited to reach special-use and cloud metadata addresses. This can potentially expose internal data or upstream provider credentials. The vulnerability requires tenant administrative configuration access but can cross the server's network boundary. The issue is fixed in version 1.43.0.

Defensive priority

Defenders should prioritize verifying exposure in Logto deployments, especially those with custom OAuth2 or OIDC connectors, and upgrade to version 1.43.0 or later. Monitoring for unusual network activity and reviewing webhook delivery configurations are also recommended.

Recommended defensive actions

  • Verify if Logto deployments are using custom OAuth2 or OIDC connectors and assess exposure.
  • Upgrade Logto to version 1.43.0 or later.
  • Monitor for unusual network activity related to webhook delivery.
  • Review webhook delivery configurations for potential security risks.
  • Perform an inventory of assets using Logto for authentication.
  • Establish a rollback plan in case issues arise during the upgrade.
  • Track the status of the CVE-2026-56739 remediation efforts.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. GitHub references offer additional context on the fix in version 1.43.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-56739 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-56739

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-56739 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56739

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.