Review reviewHigh
CVE-2026-15614
Logto
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
- CVSS
- 7.5
- EPSS
- 0.23% 13.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.24
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
The CVSS severity warrants an early asset and exposure review.
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
Confirm exposure before applying a vendor-supported change.
Confirm that Logto and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.