vulns.co
/
GKData.io MCP

IDAuthentication and identity · 2 min read

LiteSpeed Cache privileged user simulation relied on weak security tokens

Patchstack confirmed a USD 14,400 Zero Day award for an authentication-boundary flaw.

Read the primary source IDAuthentication and identityReviewed 2026-10-02

Root cause

Privileged user simulation relied on a predictable, reusable token without adequate context binding.

Demonstrated impact

Unauthenticated users could obtain administrator privileges on affected installations. The advisory identifies an operating-system limitation, so plugin installation totals do not establish affected-site counts.

Lessons for review

  • Use cryptographically secure token generation, explicit authorization, context binding and limited lifetimes.
  • Treat impersonation and user-simulation features as privileged authentication boundaries.

Award and evidence

USD 14,400Bug Bounty · Platform Confirmed

Records the explicitly isolated Zero Day component. Later platform sources report USD 16,400 paid for this single finding; the USD 2,000 difference is not apportioned or counted separately. The researcher acknowledges receiving payment; exact component settlement dates are unknown.

Read platform advisory, coordinated timeline, researcher interview and later platform retrospective.

  • Exact award and payment dates are absent. The recorded component is not the later reported total.
  • The advisory describes Windows-specific limitations.
  • The disclosed patch added token checks and lifetime controls; the researcher’s recommended random-generator improvement was deferred for compatibility.

Recorded timeline

Published
2024-08-21explicit
Public Disclosure
2024-08-19explicit · Initial platform vulnerability-database publication preceded the full advisory.
Reported
2024-08-01explicit · Report received by Patchstack; vendor contacted August 5.
Fixed
2024-08-13explicit · Release of version 6.4.
Award Announced
2024-08-21explicit · Direct award amount stated in the advisory; earliest announcement not independently established.

Sources and provenance

  1. LiteSpeed Cache CVE-2024-28000 coordinated advisory Rafie Muhammad / Patchstack · reviewed 2026-10-02
  2. Interview with John Blackbourn Maciek Palmowski / Patchstack · reviewed 2026-10-02
  3. State of WordPress Security 2025 Patchstack · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software