PT-2026-96234 · Unknown · @Sync-In/Server
CVE-2026-58271
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Sync-in Server versions prior to 2.4.0
Description
An issue exists where the account lockout mechanism fails to trigger during repeated Time-based One-Time Password (TOTP) failures. When using the
POST /api/app/sync/register endpoint to register a desktop sync client, the SyncClientsManager.register() function calls updateAccesses(user, ip, false). Due to a logic error in the updateAccesses() function, the passwordAttempts counter is written back unchanged instead of being incremented. Consequently, the counter never reaches the USER MAX PASSWORD ATTEMPTS limit of 10, allowing an attacker with valid credentials to brute-force the TOTP code.A successful guess provides a
{clientId, clientToken} pair, which can be exchanged via the POST /api/app/sync/auth/cookie endpoint for a full JSON Web Token (JWT). Additionally, an attacker can use the POST /api/auth/2fa/disable endpoint to permanently disable Multi-Factor Authentication (MFA) for the account.Recommendations
Update Sync-in Server to version 2.4.0.
As a temporary mitigation, restrict access to the
POST /api/app/sync/register endpoint or implement an IP-based rate limiter on pre-authentication credential endpoints.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Sync-In/Server