A vulnerability was found in Logto up to 1.37.1. It has been declared as critical. The impacted element is an unknown function of the file packages/core/src/routes/experience/classes/experience-interaction.ts. The manipulation results in use of single-factor authentication.

This vulnerability is reported as CVE-2026-15616. The attack can be launched remotely. No exploit exists.