PT-2026-96234 · Unknown · @Sync-In/Server

CVE-2026-58271

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sync-in Server versions prior to 2.4.0
Description An issue exists where the account lockout mechanism fails to trigger during repeated Time-based One-Time Password (TOTP) failures. When using the POST /api/app/sync/register endpoint to register a desktop sync client, the SyncClientsManager.register() function calls updateAccesses(user, ip, false). Due to a logic error in the updateAccesses() function, the passwordAttempts counter is written back unchanged instead of being incremented. Consequently, the counter never reaches the USER MAX PASSWORD ATTEMPTS limit of 10, allowing an attacker with valid credentials to brute-force the TOTP code.
A successful guess provides a {clientId, clientToken} pair, which can be exchanged via the POST /api/app/sync/auth/cookie endpoint for a full JSON Web Token (JWT). Additionally, an attacker can use the POST /api/auth/2fa/disable endpoint to permanently disable Multi-Factor Authentication (MFA) for the account.
Recommendations Update Sync-in Server to version 2.4.0. As a temporary mitigation, restrict access to the POST /api/app/sync/register endpoint or implement an IP-based rate limiter on pre-authentication credential endpoints.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58271
GHSA-274F-6W77-8QM9

Affected Products

@Sync-In/Server