CVE-2026-54047 | LaciSynchroni server up to 1.2.2 OAuth2 Login Flow config.json AuthorizeOauthAsync UID improper authentication

SecurityVulns

A vulnerability described as very critical has been identified in LaciSynchroni server up to 1.2.2. This affects the function AuthorizeOauthAsync of the file config.json of the component OAuth2 Login Flow. Such manipulation of the argument UID leads to improper authentication.

This vulnerability is referenced as CVE-2026-54047. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More