CRITICAL
LaciSynchroni
CVE published 2026-09-11
CVE-2026-54047
CVE-2026-54047 is a critical vulnerability in Laci Synchroni, a decentralized mod and appearance sync server and plugin for Dalamud. The vulnerability has a CVSS score of 9.2 and is caused by an improper authentication issue in the application's OAuth2 login flow. This allows an attacker to impersonate any target user and perform actions on their behalf. The issue has been resolved in version 1.2.3. Affec [truncated]