CVE-2026-15614

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE

Description

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references