À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2025-15662 · CVSS 8.6
CVE-2025-50455 · CVSS 9.1
CVE-2025-59172 · CVSS 8.5
CVE-2025-68686 · Fortinet FortiOS
accueil
veille
CWE-91
type de faiblesse
CWE-91
1
vulnérabilité suivie
10 juillet 2026
dernière publication
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-55789
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.
Élevée
CVSS 8.5
10/07
← Retour à la veille
Fiche CWE sur mitre.org →
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer