A vulnerability has been found in Logto up to 1.37.1 and classified as critical. This issue affects some unknown processing of the file packages/core/src/sso/SamlConnector/utils.ts of the component SAML Connector. Performing a manipulation results in insufficient verification of data authenticity.

This vulnerability is cataloged as CVE-2026-15615. It is possible to initiate the attack remotely. There is no exploit available.