CVE-2026-15614: IdP-initiated SAML sessions not reliably invalidated (replay)
Published Jul 23, 2026
·Updated
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.
Affected Software
1 affected component
Logto Logto
Event History
Jul 23, 2026
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15614?
CVE-2026-15614 has a risk rating of 52, indicating a significant security concern.
2
How do I fix CVE-2026-15614?
To fix CVE-2026-15614, ensure that IdP-initiated SAML sessions are properly invalidated after use.
3
What does CVE-2026-15614 affect?
CVE-2026-15614 affects the Logto software by failing to delete IdP-initiated SAML sessions.
4
What security issue does CVE-2026-15614 introduce?
CVE-2026-15614 introduces the risk of session replay and reuse due to improperly managed SAML sessions.
5
When was CVE-2026-15614 published?
CVE-2026-15614 was published on July 23, 2026.