These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-15617 is a critical vulnerability in Logto software, which performs principal lookup without normalizing email and identifier strings. This oversight enables principal collision and unauthorized account access via case- or Unicode-different identities. The vulnerability has a CVSS score of 9.1 and is considered critical. Affected product deployments may be vulnerable to exploitation, allowing att [truncated]
A critical vulnerability was discovered in Logto, a popular authentication and authorization platform. The vulnerability, tracked as CVE-2026-15616, allows users to bypass second-factor requirements during Single Sign-On (SSO) authentication, potentially granting unauthorized access to sensitive resources. This issue arises from the lack of enforcement of locally configured Multi-Factor Authentication (MF [truncated]
CVE-2026-15615 is a HIGH-severity vulnerability in Logto, a service that provides authentication and authorization solutions. The issue arises from the omission of validation for the SAML <Conditions> element, which allows attackers to manipulate time and audience restrictions, potentially leading to indefinite replay of assertions. This vulnerability could allow attackers to bypass security measures by r [truncated]
CVE-2026-15614 is a high-severity vulnerability in Logto that allows session replay and reuse due to silent failure in deleting IdP-initiated SAML sessions. This vulnerability affects Logto deployments relying on SAML sessions for authentication and authorization. The vulnerability class is related to improper session management. The operational impact is significant, as an attacker can exploit this vulne [truncated]
CVE-2026-15612 is a critical vulnerability in Logto that bypasses OIDC nonce validation when the nonce claim is absent from the id_token. This allows for replay of authentication tokens and weakens session-binding. The vulnerability has a CVSS score of 9.1 and is considered critical. Affected users should review and update their Logto configurations to ensure proper OIDC nonce validation. This includes ch [truncated]
A critical vulnerability, CVE-2026-15611, was found in Logto, allowing unverified email-based SSO account linking. This enables an attacker to register an identity at a permissive IdP using a victim's email and gain unauthorized access to the victim's account. The vulnerability has a CVSS score of 9.1 and is considered CRITICAL. Affected product deployments should be reviewed for exposure, and owners shou [truncated]