CVE-2026-15612

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE

Description

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references