Security Advisory

CVE-2026-15616

9.1
CRITICAL

Vulnerability Description

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
Published Date July 23, 2026
Official Source NIST NVD Advisory