CVE-2026-15614
IdP-initiated SAML sessions not reliably invalidated (replay)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
| Vendor | logto |
| Product | logto |
| Published | Jul 23, 2026 |
| Last Updated | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for logto logto
Be the first to know when new unknown vulnerabilities affecting logto logto are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Logto / Logto
1.21.0 ≤ 1.37.1