GHSA-26cp-25m8-5fgcCriticalCVSS 9.1

Logto allows unverified email-based SSO account linking, enabling an attacker to register an...

Published
July 23, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

🔗 References (4)