SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15615

HIGH · CVSS 7.5 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit the lack of validation in the SAML <Conditions> element within Logto, potentially removing time and audience restrictions on assertions. This could lead to unauthorized access through replay attacks, posing a significant risk to systems relying on SAML for authentication. Organizations utilizing Logto for identity management should prioritize addressing this issue to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15615
Severity
HIGH
CVSS
7.5
EPSS
0.18%

Original NVD Description

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.