VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

2026-07-23T20:52:13Z94833d78859324ac587a4a263e26732a7d49313463ab379b781c1fbc9961cb6a
MFA-bypassOAuthOIDCSAMLSSOaccount-takeoverauthenticationauthorizationauthorization-bypassdll-hijackinghttp2-dosinstaller-permissionskernel-ioctllocal-elevationmulti-tenantnonce-bypasspath-traversalpickleprivilege-escalationremote-code-executionunsafe-deserialization

What happened

The document is a collection of CERT/CC vulnerability notes covering multiple high-impact flaws across different products: Logto (SSO/account-linking, nonce validation issues enabling account takeover and MFA bypass), SGLang (unauthenticated remote RCE via insecure Pickle deserialization on a ZeroMQ socket), Pegatron Tdelo64.sys (unprotected IOCTLs enabling arbitrary kernel read/write and SYSTEM privilege escalation), Duplicati (improper installer permissions leading to local code execution via DLL replacement), Plane (multi-tenant authorization bypass allowing cross-workspace asset access/mod

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
94833d78859324ac587a4a263e26732a7d49313463ab379b781c1fbc9961cb6a
Enrichment time
2026-07-23T20:52:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.