Logic Flaw in Sync-in Server File Storage and Collaboration Platform
CVE-2026-41161

6.9MEDIUM

Key Information:

Vendor

Sync-in

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-41161?

The Sync-in Server, a secure open-source platform for file storage and collaboration, is susceptible to a logic flaw in its /api/auth/login endpoint. This vulnerability allows remote attackers to exploit the application by measuring response times, thus enabling them to identify valid usernames without authentication. The issue has been addressed in version 2.2.0, which mitigates the risk of unauthorized username enumeration.

Affected Version(s)

server < 2.2.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.