Junglewise Threat Intelligence

CVE-2026-15615: Logto missing SAML Conditions validation in SAML Connector

CVE-2026-15615 · Severity: info · Published 2026-07-23

Technologies: Logto. Vendors: Logto.

Executive brief

Logto, an identity management platform, contains a security flaw in how it handles SAML-based logins. The system fails to check specific security conditions in login tokens, which allows an attacker to reuse old login sessions indefinitely or bypass intended audience restrictions. This could lead to unauthorized account access and persistent sessions that should have expired.

Technical details

Logto fails to validate the SAML <Conditions> element within the SAML connector and core SSO components. This vulnerability allows an attacker to manipulate SAML assertions by removing 'NotBefore' and 'NotOnOrAfter' time constraints, as well as 'AudienceRestriction' elements. Because these conditions are not enforced, an attacker can perform a replay attack, using a previously captured valid assertion to authenticate indefinitely. The issue is located in the SAML connector utility functions and affects versions 1.12.0 through 1.37.1.

Affected products

  • Logto Logto 1.12.0 to 1.37.1

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats