CVE-2026-15617
N/A
N/A
Summary
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Logto | Logto | 1.10.1 <= 1.37.1 | affected |
Weaknesses
- CWE-178 Improper Handling of Case Sensitivity
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.