CyberRota Analysis
AI-GeneratedLogto is vulnerable due to its failure to normalize email and identifier strings during principal lookup, which can lead to principal collision and unauthorized account access through case- or Unicode-different identities. This critical vulnerability poses a significant risk to user accounts, potentially allowing attackers to impersonate legitimate users. Organizations utilizing Logto for identity management should prioritize immediate remediation to safeguard against unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.