OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-56739

HIGH · CVSS 8.5 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Logto versions prior to 1.43.0 are vulnerable due to improper validation of outbound destinations, allowing attackers with tenant administrative access to exploit webhook delivery and custom OAuth2 connectors. This can lead to exposure of internal data and upstream provider credentials by reaching sensitive cloud metadata addresses. Organizations using Logto for SaaS and AI applications should prioritize upgrading to version 1.43.0 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56739
Severity
HIGH
CVSS
8.5
EPSS
0.30%

Original NVD Description

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook delivery in packages/core/src/libraries/hook/utils.ts can reach special-use and cloud metadata addresses. Custom OAuth2 connectors can use an attacker-selected userInfoEndpoint and forward the OAuth access token in the Authorization header, while OIDC connectors can fetch an attacker-selected jwksUri. The affected operations require tenant administrative configuration access, but they cross the server's network boundary and can expose internal data or upstream provider credentials. This issue is fixed in version 1.43.0.