CVE-2026-15617

Summary

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

Affected Software

VendorProductVersion RangeStatus
LogtoLogto1.10.1 <= 1.37.1affected

Weaknesses

  • CWE-178 Improper Handling of Case Sensitivity

References