Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.
The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.