A vulnerability, which was classified as critical, was found in Logto up to 1.37.1. This vulnerability affects unknown code of the file single-sign-on-guard.ts of the component Principal Lookup. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is listed as CVE-2026-15617. The attack may be performed from remote. There is no available exploit.