Junglewise Threat Intelligence

CVE-2026-15611: Logto unverified email-based SSO account linking

CVE-2026-15611 · Severity: info · CVSS 8.1 · Published 2026-07-23

Technologies: Logto. Vendors: Logto.

Executive brief

Logto, an identity management platform, contains a flaw in how it links user accounts during Single Sign-On (SSO) logins. An attacker can use a third-party identity provider that does not verify email addresses to claim a victim's email address. When the attacker logs in via SSO, Logto may automatically link this unverified identity to the victim's existing account, granting the attacker full unauthorized access to the victim's data and profile.

Technical details

A vulnerability in Logto's Single Sign-On (SSO) implementation allows for insecure account linking based on unverified email addresses. The root cause is located in the SSO verification logic, specifically within the enterprise SSO verification routes, where the system fails to ensure that an email address provided by an external Identity Provider (IdP) has been verified before linking it to an existing local account. An attacker can exploit this by creating an account on a 'permissive' IdP (one that does not require email verification) using a victim's email address. Upon authenticating via that IdP, Logto links the external identity to the victim's account, resulting in a full account takeover. This affects Logto versions 1.11.0 through 1.37.1.

Affected products

  • Logto Logto 1.11.0 to 1.37.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats