External risk intelligence

Logto Unverified Email SSO Account Linking Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-15611

Logto is an identity and access management solution. As an identity provider or authentication service, it is designed to be public-facing to facilitate user login, SSO, and identity verification across web applications, making its authentication endpoints inherently exposed to the internet by design.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This issue in Logto allows attackers to link a victim's email to a new account using a permissive identity provider, potentially granting unauthorized access to the victim's account. The technology affected is identity and access management. The main concern is confirming relevance and exposure due to the potential for unauthorized account access.

  • Unverified email linking can hijack user accounts.
  • Critical for identity services; confirm if used.
  • Assess if Logto manages your user identities.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by using a victim's email address to register an account with a freely accessible identity provider. Once registered, the attacker can then link this identity to the victim's Logto account, effectively taking over their access without needing any prior credentials or interaction from the victim. This could lead to unauthorized access and modification of the victim's data or services.

  • Requires network access.
  • Unverified email links accounts.
  • Unauthorized account access.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could link a victim's email to a rogue identity at a permissive identity provider, potentially gaining unauthorized access to the victim's account. This could impact system data and user data through unauthorized access.

  • Account access and user data at risk.
  • Unverified email linking enables unauthorized access.
  • Unauthorized access to accounts and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Logto, which allows unverified email-based SSO account linking, could be exploited by an attacker to gain unauthorized access to user accounts. Ownership of the remediation effort likely falls to the platform or identity and access management (IAM) team responsible for the Logto deployment, in coordination with application owners who rely on it for authentication. The immediate first step is to identify all instances of Logto within the environment, assess their reachability and criticality, and confirm the accountable owner for each.

  • Platform/IAM team owns the issue.
  • Verify Logto instances and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Logto?

Logto is an identity and access management (IAM) solution. It functions as an authentication service that developers use to handle user logins, single sign-on (SSO), and identity verification across their web applications.

What does CVE-2026-15611 mean?

This vulnerability is classified as Improper Authentication (CWE-287). It exists because the software fails to properly verify emails during the SSO account linking process, allowing an attacker to link an identity they control to someone else's existing account.

How does an attacker trigger this vulnerability?

An attacker triggers this by registering an account with a permissive identity provider using a victim's email address. The bug does not require the victim to perform any action, nor does it require the attacker to compromise the victim's credentials; it relies entirely on the flaw in the account linking logic.

Is my Logto instance at risk?

According to Halo Surface Signal, Logto is inherently designed to be public-facing to support user authentication, meaning it is typically reachable from the internet. If you use Logto to manage user identities, you should consider your implementation relevant to this issue.

What should I do to respond to this issue?

First, locate all Logto deployments within your environment and identify the teams responsible for managing them. Work with those teams to confirm if your current configuration enables account linking with external identity providers and assess the potential impact on your users.

References