CVE-2026-15616

Summary

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.

Affected Software

VendorProductVersion RangeStatus
LogtoLogto1.19.0 <= 1.37.1affected

Weaknesses

  • CWE-308 Use of Single-factor Authentication

References