CVE-2026-55789
Last modified
CVE-2026-55789 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| logto-io | logto | < 1.41.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55789?
How severe is CVE-2026-55789?
How do I fix CVE-2026-55789?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55780NanaZip is the 7-Zip derivative intended for the modern Wind…2.4
- CVE-2026-55781NanaZip is the 7-Zip derivative intended for the modern Wind…2.4
- CVE-2026-55782NanaZip is the 7-Zip derivative intended for the modern Wind…2.4
- CVE-2026-55783NanaZip is the 7-Zip derivative intended for the modern Wind…2.4
- CVE-2026-55784free5GC is an open-source implementation of the 5G core netw…7.5
- CVE-2026-55785free5GC is an open-source implementation of the 5G core netw…3.7
- CVE-2026-5579A vulnerability was determined in CodeAstro Online Classroom…6.3
- CVE-2026-55790Craft CMS is a content management system (CMS). In versions …7.4
- CVE-2026-55791Craft CMS is a content management system (CMS). Versions 4.0…6.9
- CVE-2026-55792Craft CMS is a content management system (CMS). In versions …6
- CVE-2026-55793Craft CMS is a content management system (CMS). In versions …5.9
- CVE-2026-55794Craft CMS is a content management system (CMS). In versions …8.7
Are you affected by CVE-2026-55789?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
