CVE-2026-15616
Critical · CVSS 9.1- CVSS
- 9.1
- nvd
- EPSS
- 0.19%
- 10th pct
- KEV
- No
- Class
- oss containerizable
- CWE-308
Description
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
References
Status: profiled · ingested 2026-07-27T18:00:00.000Z