SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-54047

CRITICAL · CVSS 9.2 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Laci Synchroni application is vulnerable due to an improper authentication flaw in its OAuth2 login flow, allowing attackers to impersonate any user by manipulating the `UID` field in their local configuration file. This critical vulnerability can lead to unauthorized actions on behalf of targeted users, posing significant risks to user data and account integrity. Organizations using versions prior to 1.2.3 should prioritize immediate updates to mitigate this security threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54047
Severity
CRITICAL
CVSS
9.2
EPSS
0.23%

Original NVD Description

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available.