PT-2026-96251 · Unknown · @Sync-In/Server
CVE-2026-58272
·
Published
2026-09-21
·
Updated
2026-09-23
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sync-in Server versions prior to 2.4.1
Description
An observable timing discrepancy exists in the login process. When an authentication attempt is made for a nonexistent account, the system returns a response immediately without performing the bcrypt comparison used for existing accounts. This occurs because the
validateUser() function returns null as soon as a user is not found, skipping the comparePassword() function and its associated cryptographic work. Consequently, an unauthenticated attacker can measure response times at the '/api/auth/login' endpoint to distinguish between non-existent accounts (near-instant rejection) and existing accounts (consistently slower due to bcrypt comparison). This allows for the enumeration of valid usernames or email addresses, which can be used to facilitate credential-stuffing, password-spraying, and phishing attacks.Recommendations
Update to version 2.4.1.
As a temporary workaround, restrict access to the '/api/auth/login' endpoint to minimize the risk of account enumeration.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Sync-In/Server