← Back to feed
vulnerabilities1 source · 3h ago

CVE-2026-15611: Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauth

CVE-2026-15611 disclosed: Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.

No Reader read of this story yet.

Perspectives

The story's competing narratives, side by side — grouped by stance, with every outlet's origin and affiliation visible.

Perspective analysis pending — it generates as coverage from more origins arrives.

What to expect

First-order impacts with their likely second-order effects — direction and horizon per node.

Impact analysis pending.

Sources (1)

CVE-2026-15611: Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauth — Prism