← לוח פגיעויות

CVE-2026-15617

טרם דורגה

טרם דורג — בהתאם למדיניות NVD מאפריל 2026, רוב ה-CVE אינם מנותחים מיידית. ציון EPSS (אם קיים) עדיין מוצג.

תיאור (מקור, אנגלית)

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

מדדים

EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-24/7/2026

קישורים