CVE-2026-15617

NONE
CVSS v3
CVSS v2
EPSS (exploit probability)
CWE

Description

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references