CVE-2026-15615
טרם דורגה
תיאור (מקור, אנגלית)
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.
מדדים
- EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-25/7/2026