PatchSiren

LaciSynchroni CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL LaciSynchroni CVE published 2026-09-11

CVE-2026-54047

CVE-2026-54047 is a critical vulnerability in Laci Synchroni, a decentralized mod and appearance sync server and plugin for Dalamud. The vulnerability has a CVSS score of 9.2 and is caused by an improper authentication issue in the application's OAuth2 login flow. This allows an attacker to impersonate any target user and perform actions on their behalf. The issue has been resolved in version 1.2.3. Affec [truncated]