Beyond CRTO: pwnlift 22 Jun 2026 17 min read CVE TL;DR While working through CRTO, I found pwnlift exposed through passwordless sudo on the team server VM. The upload handler permitted arbitrary file write as root via symlink traversal, and the first