VU#492466: Logto Identity Plat... Note

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

Logto, an identity and access management system, suffers from multiple vulnerabilities in its authentication and authorization pipeline. These flaws weaken security for SaaS and AI applications using OIDC, OAuth 2.1, and SAML. One vulnerability allows account takeover by linking SSO identities to existing accounts without verifying the email. Another allows bypassing nonce verification in OIDC, potentially enabling replay attacks. Logto also mishandles SAML sessions, permitting replayed assertions to authorize multiple sign-ins due to separate lookup and deletion steps. Bypassing SAML Conditions checks allows attackers to circumvent time-based validation on forged or replayed assertions. Crucially, Logto fails to enforce MFA for SSO logins, allowing federated accounts to bypass local security. Inconsistent attribute comparisons in SSO flows can lead to incorrect identity resolution and unintended account linking. These issues collectively create pathways for unauthorized access, compromising account ownership and session integrity. Until patches are available, administrators can mitigate risks by managing email provisioning carefully, avoiding social SAML connectors, and enforcing MFA at upstream IdPs.