Executive brief
Logto, an identity management platform, contains a flaw where it fails to require multi-factor authentication (MFA) when users sign in using Single Sign-On (SSO). This means that even if an organization has mandated a second layer of security for its users, an attacker who gains control of a user's SSO credentials can bypass these local security requirements. This could lead to unauthorized access to sensitive corporate applications and data.
Technical details
An authentication bypass vulnerability exists in Logto versions 1.19.0 through 1.37.1. The root cause is a failure in the 'experience-interaction' component to enforce locally configured Multi-Factor Authentication (MFA) policies when a user authenticates via a Single Sign-On (SSO) provider. An attacker with valid SSO credentials can successfully authenticate to the Logto instance without being prompted for the secondary verification factors that would otherwise be required for local accounts. This bypasses the intended security posture of the identity provider. The vulnerability is located in the core routing logic responsible for managing user interaction sessions during the authentication flow.
Affected products
- Logto Logto 1.19.0 to 1.37.1
Timeline
- 2026-07-23: advisory: NVD published CVE-2026-15616