Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55789— Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers

CVSS 8.5 · High EPSS 0.30% · P22

Affected Version Matrix 1

VendorProductVersion RangeStatus
logto-iologto< 1.41.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-55789

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
Source: CVE Program / CVE List V5
Vulnerability Description
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
XML注入(XPath盲注)
Source: CVE Program / CVE List V5
Vulnerability Title
logto-io logto 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
logto-io logto是logto-io组织的一个身份认证和用户管理平台。 logto-io logto 1.41.0之前版本存在输入验证错误漏洞,该漏洞源于使用samlify 2.10.0构建SAML响应时,对用户可控的个人资料属性(如名称、电子邮件和自定义属性映射值)未进行转义处理,导致经过身份验证的低权限用户可在个人资料属性中插入XML标记,从而伪造SAML属性实现权限提升。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
logto-iologto < 1.41.0 -

II. Public POCs for CVE-2026-55789

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 8949 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-55789

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55789 (1)

Vendor Pages for CVE-2026-55789 (1)

Other References for CVE-2026-55789 (1)

Same Patch Batch · logto-io · 2026-07-10 · 4 CVEs total

CVE-2026-553778.1 HIGHLogto: Account Center MFA management step-up bypass via WebAuthn registration verification
CVE-2026-553706.4 MEDIUMLogto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violati
CVE-2026-547146.1 MEDIUMLogto: XSS via unescaped RelayState in SAML auto-submit form

IV. Related Vulnerabilities

V. Comments for CVE-2026-55789

No comments yet


Leave a comment