PT-2026-96251 · Unknown · @Sync-In/Server

CVE-2026-58272

·

Published

2026-09-21

·

Updated

2026-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sync-in Server versions prior to 2.4.1
Description An observable timing discrepancy exists in the login process. When an authentication attempt is made for a nonexistent account, the system returns a response immediately without performing the bcrypt comparison used for existing accounts. This occurs because the validateUser() function returns null as soon as a user is not found, skipping the comparePassword() function and its associated cryptographic work. Consequently, an unauthenticated attacker can measure response times at the '/api/auth/login' endpoint to distinguish between non-existent accounts (near-instant rejection) and existing accounts (consistently slower due to bcrypt comparison). This allows for the enumeration of valid usernames or email addresses, which can be used to facilitate credential-stuffing, password-spraying, and phishing attacks.
Recommendations Update to version 2.4.1. As a temporary workaround, restrict access to the '/api/auth/login' endpoint to minimize the risk of account enumeration.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58272
GHSA-29HQ-23M2-2J47

Affected Products

@Sync-In/Server