Skip to main content

CVE-2026-63203: CWE-862: Missing Authorization in logto-io logto

0
High
VulnerabilityCVE-2026-63203cvecve-2026-63203cwe-862
Published: 09/24/2026 (09/24/2026, 15:18:32 UTC)
Source: CVE Database V5
Vendor/Project: logto-io
Product: logto

Description

CVE-2026-63203 is a high-severity vulnerability in logto versions from 1.31.0 up to but not including 1.42.0. It involves missing authorization checks in the Account API handlers that allow a user holding a same-user access token with only the openid scope to retrieve stored social or enterprise SSO provider access tokens. This bypasses the intended consent boundary because the handlers do not require the identities scope. Exploitation requires federated token-set storage to be enabled and the affected user to have authenticated through a supported connector. The issue is fixed in version 1.42.0.

CVSS v3.1

Score 7.6high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Affected software

logto-io

logto

Affected versions
>=1.31.0 <1.42.0
GitHub Actionsmore threats →ai
logto-io/logto
pkg:github/logto-io/logto
Affected versions
>=1.31.0 <1.42.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 16:17:43 UTC

Technical Analysis

Logto versions >=1.31.0 and <1.42.0 contain a missing authorization vulnerability (CWE-862) in the Account API handlers located in packages/core/src/routes/account/third-party-tokens.ts. Specifically, callers with a same-user access token scoped only with openid can access endpoints GET /api/my-account/identities/{target}/access-token and GET /api/my-account/sso-identities/{connectorId}/access-token to retrieve stored social or enterprise SSO provider access tokens. These handlers authenticate the user but do not enforce the identities scope, which is required to protect related identity-detail operations, thereby bypassing the intended consent boundary. Exploitation requires that federated token-set storage is enabled and that the user has authenticated via a supported connector. A low-trust application could misuse the disclosed provider token against upstream APIs within the token's granted scopes. The vulnerability is resolved in version 1.42.0.

Potential Impact

An attacker with a same-user access token limited to the openid scope can retrieve stored third-party access tokens without proper authorization. This can lead to unauthorized access to upstream APIs within the scope of the disclosed tokens, potentially exposing sensitive information or allowing actions on behalf of the user. The vulnerability does not affect availability but impacts confidentiality and partially integrity.

Mitigation Recommendations

Upgrade to logto version 1.42.0 or later, where this missing authorization issue is fixed. There is no indication that temporary mitigations are available. Users should ensure federated token-set storage is configured securely and review access token scopes. Patch status is confirmed fixed in 1.42.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-07-15T22:19:06.905Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ab549d5f7a7c54106846f26

Added to database: 09/24/2026, 16:03:33 UTC

Last enriched: 09/24/2026, 16:17:43 UTC

Last updated: 09/24/2026, 16:27:49 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses