PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15617 Logto CVE debrief

CVE-2026-15617 is a critical vulnerability in Logto software, which performs principal lookup without normalizing email and identifier strings. This oversight enables principal collision and unauthorized account access via case- or Unicode-different identities. The vulnerability has a CVSS score of 9.1 and is considered critical. Affected product deployments may be vulnerable to exploitation, allowing attackers to gain unauthorized access. Users of Logto software should be aware of this vulnerability and take necessary precautions to prevent exploitation.

Vendor
Logto
Product
Unknown
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-27
Advisory published
2026-07-23
Advisory updated
2026-07-27

Who should care

Users of Logto software, security teams, and operators of affected systems should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes reviewing official advisories, updating affected systems, and monitoring for suspicious activity. Vulnerability management and security teams should prioritize this vulnerability due to its critical severity and potential impact on system security.

Technical summary

The vulnerability exists in the Logto software, specifically in the way it handles principal lookup. The software fails to normalize email and identifier strings, allowing for principal collision and unauthorized account access. This can be exploited by attackers using case- or Unicode-different identities. The vulnerability has a CVSS score of 9.1 and is considered critical.

Defensive priority

High

Recommended defensive actions

  • Review and update Logto software to ensure normalization of email and identifier strings
  • Implement additional security measures to prevent principal collision and unauthorized account access
  • Monitor Logto software for suspicious activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record was published on 2026-07-23T16:17:14.423Z and was last modified on 2026-07-27T16:17:03.047Z. The NVD entry is currently Deferred. The Logto software performs principal lookup without normalizing email and identifier strings, which enables principal collision and unauthorized account access via case- or Unicode-different identities. The CVE record was created based on limited source information and may not fully represent the vulnerability's scope or impact. Defenders should verify affected product deployments and review official advisories for further details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15617 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15617

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15617 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15617

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/logto-io/logto/blob/ea3ede35028dfd0bbb6d7b239623ce0e7f6cdff8/packages/core/src/libraries/verification-helpers/single-sign-on-guard.ts

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.