CVE-2026-15616
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unau
CVSS
9.1
Crítico
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Publicado: 23 jul 2026 · Última mod.: 27 jul 2026 · CWE-308
0.2%EPSS · 30 días0.3%
2026-07-242026-08-02
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.