logo

CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling

ID: 4c417baf-5f77-5b8d-abaa-be670768de20

STIX ID: report--4c417baf-5f77-5b8d-abaa-be670768de20

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

CERT/CC disclosed six vulnerabilities in the Logto identity platform (VU#492466) that can enable account takeover, MFA bypass, token replay, and SAML assertion replay or timing bypasses; no vendor fixes or confirmed exploitation exist yet and administrators are advised to apply mitigations such as enforcing upstream MFA, avoiding email-shared local accounts, shortening sessions, and monitoring auth logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.