Description
Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available.
Published: 2026-09-11
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover / User Impersonation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the backend relies on a client‑side configuration file to identify the user. When a user edits the UID field in the config.json before authenticating, the server accepts it without verifying that the OAuth2 token actually belongs to that UID. This flaw allows the attacker to assume any account, performing authorized actions on its behalf. The weakness is a classic authentication bypass (CWE‑287) coupled with lack of proper input validation (CWE‑602) and insecure handling of privileged tokens (CWE‑349).

Affected Systems

This issue affects LaciSynchroni server The affected component is the OAuth2 authentication endpoint located in the SecretKeyAuthenticatorService. Customers running the v1.2.1 and v1.2.2 builds, or any manual deployment using those source tags, are vulnerable.

Risk and Exploitability

The CVSS score of 9.2 places this flaw in the critical range. Due to the lack of a network‑access requirement, the EPSS score is not available, implying that the exploitation likelihood is not quantified in the public dataset. However, the attacker only needs local access to the client configuration file or the ability to modify it before the login process; no external network attack is described. Consequently, internal threat actors or compromised clients can exploit the flaw. The flaw is not currently listed in CISA's KEV catalog, but the high severity warrants immediate remediational action. The server now validates the OAuth2 identity against the requested UID, eliminating the impersonation path once updated to v1.2.3.

Generated by OpenCVE AI on September 11, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update LaciSynchroni server to version 1.2.3 or later to apply the OAuth2 validation fix.
  • Ensure the config.json file is applying file‑ review of user accounts and session logs for suspicious activity or unauthorized changes, and reset credentials as needed.
  • Apply strict file permissions to the client’s config.json to prevent unauthorized edits.

Generated by OpenCVE AI on September 11, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lacisynchroni
Lacisynchroni server
Vendors & Products Lacisynchroni
Lacisynchroni server

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID` field inside the `Authentications` object of a user's local `config.json` file. By manually editing this local file on their PC prior to logging in, a user can supply an arbitrary UID. Because the server fails to validate that the authenticated OAuth2 identity matches the requested UID, an attacker can fully impersonate any target user and perform actions on their behalf. This issue has been resolved in version 1.2.3. The patch modifies `AuthorizeOauthAsync` inside the `SecretKeyAuthenticatorService` to strictly bind the lookup of the requested User ID (`requestedUid`) to the record of the successfully authenticated identity (`primaryUid`). The server will no longer load or return session tokens for a requested UID unless it matches the verified, authenticated database record. No known workarounds are available.
Title Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation
Weaknesses CWE-287
CWE-349
CWE-602
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lacisynchroni Server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-11T19:17:54.621Z

Reserved: 2026-06-11T16:57:50.020Z

Link: CVE-2026-54047

cve-icon Vulnrichment

Updated: 2026-09-11T19:17:49.012Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T17:17:10.477

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:55:42Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-349

    Acceptance of Extraneous Untrusted Data With Trusted Data

  • CWE-602

    Client-Side Enforcement of Server-Side Security