Executive brief
Logto is an open-source identity infrastructure used to manage user authentication and sign-in experiences. A security flaw in how the system handles email addresses and identifiers allows attackers to potentially gain unauthorized access to accounts. By using variations of an email address (such as changing capitalization or using special Unicode characters), an attacker can cause the system to confuse two different identities, leading to account takeover or unauthorized access to sensitive user data.
Technical details
A vulnerability exists in Logto's principal lookup mechanism within the Single Sign-On (SSO) guard and identity verification components. The application fails to normalize email and identifier strings (e.g., via case folding or Unicode normalization) before performing lookups. This allows for principal collisions where an attacker can register or authenticate using a visually or logically similar identifier (such as 'user@example.com' vs 'User@example.com' or Unicode equivalents) that the system treats as a different record during registration but matches to an existing principal during lookup. This can lead to unauthorized account access or session hijacking. The issue is present in versions 1.10.1 through 1.37.1.
Affected products
- Logto Logto 1.10.1 to 1.37.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory