VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling
2026-07-23T20:52:13Z•94833d78859324ac587a4a263e26732a7d49313463ab379b781c1fbc9961cb6a
MFA-bypassOAuthOIDCSAMLSSOaccount-takeoverauthenticationauthorizationauthorization-bypassdll-hijackinghttp2-dosinstaller-permissionskernel-ioctllocal-elevationmulti-tenantnonce-bypasspath-traversalpickleprivilege-escalationremote-code-executionunsafe-deserialization
What happened
The document is a collection of CERT/CC vulnerability notes covering multiple high-impact flaws across different products: Logto (SSO/account-linking, nonce validation issues enabling account takeover and MFA bypass), SGLang (unauthenticated remote RCE via insecure Pickle deserialization on a ZeroMQ socket), Pegatron Tdelo64.sys (unprotected IOCTLs enabling arbitrary kernel read/write and SYSTEM privilege escalation), Duplicati (improper installer permissions leading to local code execution via DLL replacement), Plane (multi-tenant authorization bypass allowing cross-workspace asset access/mod
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 94833d78859324ac587a4a263e26732a7d49313463ab379b781c1fbc9961cb6a
- Enrichment time
- 2026-07-23T20:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.