A vulnerability was found in Logto up to 1.37.1. It has been classified as critical. The affected element is an unknown function of the file packages/core/src/libraries/verification-helpers/single-sign-on.ts of the component Single Sign-On. The manipulation leads to authentication bypass by capture-replay.

This vulnerability is documented as CVE-2026-15614. The attack can be initiated remotely. There is not any exploit available.