{"schema_version":1,"title":"Logto vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Logto: 2 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-63203, was published on 24 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/logto","json_url":"https://junglewise.ai/threats/vendors/logto.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/logto","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":15,"critical":0,"exploited":0,"last_7_days":2,"last_30_days":4,"last_90_days":15,"last_365_days":15},"latest":[{"cve":"CVE-2026-63203","cvss":7.6,"epss":0.0031,"slug":"cve-2026-63203-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and","title":"Logto Account API authorization bypass for third-party tokens","severity":"high","exploited":false,"published_at":"2026-09-24T16:17:08.7+00:00","url":"https://junglewise.ai/threats/cve-2026-63203-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and"},{"cve":"CVE-2026-56739","epss":0.003,"slug":"cve-2026-56739-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and","title":"Logto SSRF in webhook and connector endpoints","severity":"info","exploited":false,"published_at":"2026-09-24T16:17:07.803+00:00","url":"https://junglewise.ai/threats/cve-2026-56739-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and"},{"cve":"CVE-2026-82263","cvss":6.8,"epss":0.0046,"slug":"cve-2026-82263-logto-server-side-request-forgery-in-oidc-connector-creation","title":"Logto server-side request forgery in OIDC connector creation","severity":"medium","exploited":false,"published_at":"2026-08-28T20:20:16.79+00:00","url":"https://junglewise.ai/threats/cve-2026-82263-logto-server-side-request-forgery-in-oidc-connector-creation"},{"cve":"CVE-2026-82262","cvss":6.8,"epss":0.0046,"slug":"cve-2026-82262-logto-server-side-request-forgery-in-webhook-test-endpoint","title":"Logto server-side request forgery in webhook test endpoint","severity":"medium","exploited":false,"published_at":"2026-08-28T20:20:16.643+00:00","url":"https://junglewise.ai/threats/cve-2026-82262-logto-server-side-request-forgery-in-webhook-test-endpoint"},{"cve":"CVE-2026-63188","cvss":4,"epss":0.0054,"slug":"cve-2026-63188-logto-logto-tunnel-path-traversal-in-static-file-serving","title":"Logto @logto/tunnel path traversal in static file serving","severity":"high","exploited":false,"published_at":"2026-08-19T20:24:06+00:00","url":"https://junglewise.ai/threats/cve-2026-63188-logto-logto-tunnel-path-traversal-in-static-file-serving"},{"cve":"CVE-2026-15617","slug":"cve-2026-15617-logto-account-takeover-via-improper-identifier-normalization","title":"Logto account takeover via improper identifier normalization","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.423+00:00","url":"https://junglewise.ai/threats/cve-2026-15617-logto-account-takeover-via-improper-identifier-normalization"},{"cve":"CVE-2026-15616","cvss":0,"slug":"cve-2026-15616-logto-mfa-bypass-during-sso-authentication","title":"Logto MFA bypass during SSO authentication","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.33+00:00","url":"https://junglewise.ai/threats/cve-2026-15616-logto-mfa-bypass-during-sso-authentication"},{"cve":"CVE-2026-15615","slug":"cve-2026-15615-logto-missing-saml-conditions-validation-in-saml-connector","title":"Logto missing SAML Conditions validation in SAML Connector","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.237+00:00","url":"https://junglewise.ai/threats/cve-2026-15615-logto-missing-saml-conditions-validation-in-saml-connector"},{"cve":"CVE-2026-15614","cvss":0,"slug":"cve-2026-15614-logto-session-replay-vulnerability-in-idp-initiated-saml-sessions","title":"Logto session replay vulnerability in IdP-initiated SAML sessions","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.143+00:00","url":"https://junglewise.ai/threats/cve-2026-15614-logto-session-replay-vulnerability-in-idp-initiated-saml-sessions"},{"cve":"CVE-2026-15612","slug":"cve-2026-15612-logto-oidc-nonce-validation-bypass-in-oidcconnector","title":"Logto OIDC nonce validation bypass in OidcConnector","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.047+00:00","url":"https://junglewise.ai/threats/cve-2026-15612-logto-oidc-nonce-validation-bypass-in-oidcconnector"},{"cve":"CVE-2026-15611","cvss":8.1,"slug":"cve-2026-15611-logto-unverified-email-based-sso-account-linking","title":"Logto unverified email-based SSO account linking","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:13.947+00:00","url":"https://junglewise.ai/threats/cve-2026-15611-logto-unverified-email-based-sso-account-linking"},{"cve":"CVE-2026-55789","cvss":8.5,"slug":"cve-2026-55789-logto-xml-injection-in-saml-idp-profile-attributes","title":"Logto XML injection in SAML IdP profile attributes","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:47.933+00:00","url":"https://junglewise.ai/threats/cve-2026-55789-logto-xml-injection-in-saml-idp-profile-attributes"},{"cve":"CVE-2026-55377","cvss":8.1,"slug":"cve-2026-55377-logto-mfa-bypass-in-account-center-step-up-verification","title":"Logto MFA bypass in Account Center step-up verification","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:46.46+00:00","url":"https://junglewise.ai/threats/cve-2026-55377-logto-mfa-bypass-in-account-center-step-up-verification"},{"cve":"CVE-2026-55370","cvss":6.4,"slug":"cve-2026-55370-logto-totp-authentication-bypass-via-capture-replay","title":"Logto TOTP authentication bypass via capture-replay","severity":"medium","exploited":false,"published_at":"2026-07-10T20:16:46.333+00:00","url":"https://junglewise.ai/threats/cve-2026-55370-logto-totp-authentication-bypass-via-capture-replay"},{"cve":"CVE-2026-54714","cvss":6.1,"slug":"cve-2026-54714-logto-reflected-xss-in-saml-auto-submit-form","title":"Logto reflected XSS in SAML auto-submit form","severity":"medium","exploited":false,"published_at":"2026-07-10T20:16:46.173+00:00","url":"https://junglewise.ai/threats/cve-2026-54714-logto-reflected-xss-in-saml-auto-submit-form"}],"vendor":{"hub":true,"name":"Logto","slug":"logto","homepage":"https://logto.io/","description":"An open-source identity infrastructure for developers.","url":"https://junglewise.ai/threats/vendors/logto"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-55789","cvss":8.5,"slug":"cve-2026-55789-logto-xml-injection-in-saml-idp-profile-attributes","title":"Logto XML injection in SAML IdP profile attributes","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:47.933+00:00","url":"https://junglewise.ai/threats/cve-2026-55789-logto-xml-injection-in-saml-idp-profile-attributes"},{"cve":"CVE-2026-55377","cvss":8.1,"slug":"cve-2026-55377-logto-mfa-bypass-in-account-center-step-up-verification","title":"Logto MFA bypass in Account Center step-up verification","severity":"high","exploited":false,"published_at":"2026-07-10T20:16:46.46+00:00","url":"https://junglewise.ai/threats/cve-2026-55377-logto-mfa-bypass-in-account-center-step-up-verification"},{"cve":"CVE-2026-63203","cvss":7.6,"epss":0.0031,"slug":"cve-2026-63203-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and","title":"Logto Account API authorization bypass for third-party tokens","severity":"high","exploited":false,"published_at":"2026-09-24T16:17:08.7+00:00","url":"https://junglewise.ai/threats/cve-2026-63203-logto-is-the-modern-open-source-auth-infrastructure-for-saas-and"},{"cve":"CVE-2026-63188","cvss":4,"epss":0.0054,"slug":"cve-2026-63188-logto-logto-tunnel-path-traversal-in-static-file-serving","title":"Logto @logto/tunnel path traversal in static file serving","severity":"high","exploited":false,"published_at":"2026-08-19T20:24:06+00:00","url":"https://junglewise.ai/threats/cve-2026-63188-logto-logto-tunnel-path-traversal-in-static-file-serving"},{"cve":"CVE-2026-82263","cvss":6.8,"epss":0.0046,"slug":"cve-2026-82263-logto-server-side-request-forgery-in-oidc-connector-creation","title":"Logto server-side request forgery in OIDC connector creation","severity":"medium","exploited":false,"published_at":"2026-08-28T20:20:16.79+00:00","url":"https://junglewise.ai/threats/cve-2026-82263-logto-server-side-request-forgery-in-oidc-connector-creation"},{"cve":"CVE-2026-82262","cvss":6.8,"epss":0.0046,"slug":"cve-2026-82262-logto-server-side-request-forgery-in-webhook-test-endpoint","title":"Logto server-side request forgery in webhook test endpoint","severity":"medium","exploited":false,"published_at":"2026-08-28T20:20:16.643+00:00","url":"https://junglewise.ai/threats/cve-2026-82262-logto-server-side-request-forgery-in-webhook-test-endpoint"},{"cve":"CVE-2026-55370","cvss":6.4,"slug":"cve-2026-55370-logto-totp-authentication-bypass-via-capture-replay","title":"Logto TOTP authentication bypass via capture-replay","severity":"medium","exploited":false,"published_at":"2026-07-10T20:16:46.333+00:00","url":"https://junglewise.ai/threats/cve-2026-55370-logto-totp-authentication-bypass-via-capture-replay"},{"cve":"CVE-2026-54714","cvss":6.1,"slug":"cve-2026-54714-logto-reflected-xss-in-saml-auto-submit-form","title":"Logto reflected XSS in SAML auto-submit form","severity":"medium","exploited":false,"published_at":"2026-07-10T20:16:46.173+00:00","url":"https://junglewise.ai/threats/cve-2026-54714-logto-reflected-xss-in-saml-auto-submit-form"},{"cve":"CVE-2026-15611","cvss":8.1,"slug":"cve-2026-15611-logto-unverified-email-based-sso-account-linking","title":"Logto unverified email-based SSO account linking","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:13.947+00:00","url":"https://junglewise.ai/threats/cve-2026-15611-logto-unverified-email-based-sso-account-linking"},{"cve":"CVE-2026-15616","cvss":0,"slug":"cve-2026-15616-logto-mfa-bypass-during-sso-authentication","title":"Logto MFA bypass during SSO authentication","severity":"info","exploited":false,"published_at":"2026-07-23T16:17:14.33+00:00","url":"https://junglewise.ai/threats/cve-2026-15616-logto-mfa-bypass-during-sso-authentication"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"Logto","slug":"logto","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/logto"}]}