These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. Prior to version 1.43.0, Logto's webhook delivery and custom OAuth2 and OIDC connectors can be exploited to reach special-use and cloud metadata addresses, potentially exposing internal data or upstream provider credentials. This issue requires tenant administrative configur [truncated]
CVE-2026-82263 is a high-severity vulnerability in Logto, a software identity and access management solution. The vulnerability is caused by a server-side request forgery (SSRF) issue in the OIDC SSO connector creation endpoint, which allows tenant administrators with Management API credentials to supply arbitrary internal URLs and trigger HTTP GET requests to private network services. The response conten [truncated]
CVE-2026-82262 is a server-side request forgery vulnerability in Logto through version 1.42.0. The vulnerability exists in the POST /api/hooks/:id/test endpoint, which accepts arbitrary URLs without host validation. This allows tenant administrators with Management API tokens to make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-62317 was published on 2026-08-19T20:17:19.890Z and has not been modified since then. The NVD entry is currently 7.5 HIGH. The vulnerability affects Logto, an open-source auth infrastructure for SaaS and AI apps, specifically its email subaddressing blocklist feature in packages/core/src/libraries/sign-in-exper [truncated]
CVE-2026-55789 is a high-severity vulnerability in Logto's self-hosted SAML application IdP. Prior to version 1.41.0, an authenticated low-privilege user could inject XML markup into profile attributes, allowing the creation of forged SAML attributes, such as arbitrary roles, and potentially leading to privilege escalation at relying Service Providers that authorize on SAML attributes. This vulnerability [truncated]
CVE-2026-55377 is a high-severity vulnerability in Logto's Account Center step-up check. Prior to version 1.41.0, an attacker could create and verify a WebAuthn registration verification record using only an existing Account API bearer token. This allowed for MFA factor management without proving possession of an existing password, identifier, or MFA factor. The vulnerability has a CVSS score of 8.1 and i [truncated]
CVE-2026-55370 is a medium-severity vulnerability in Logto's TOTP verification process. An attacker can replay a successfully used TOTP code within the RFC 6238 acceptance window. This issue is fixed in version 1.41.0. The vulnerability affects users of Logto's authentication infrastructure who use TOTP for multi-factor authentication. The issue arises from the verifier using otplib's stateless check with [truncated]
CVE-2026-54714 is a reflected cross-site scripting (XSS) vulnerability in the Logto open-source auth infrastructure for SaaS and AI apps. The vulnerability exists in the SAML application flow, specifically in the @logto/core package. An attacker could inject script into the Logto tenant origin after a user completes login by crafting a RelayState value in the GET or POST /api/saml/:id/authn request. The i [truncated]