Security Advisory

CVE-2026-15615

7.5
HIGH

Vulnerability Description

Logto omits validation of the SAML element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
Published Date July 23, 2026
Official Source NIST NVD Advisory