Timing Discrepancy Vulnerability in Sync-in Server by Sync-in
CVE-2026-58272
5.3MEDIUM
What is CVE-2026-58272?
Sync-in Server, an open-source platform designed for file storage and collaboration, has a vulnerability affecting its login endpoint. Due to an observable timing discrepancy, authentication attempts made against nonexistent accounts return responses without engaging the bcrypt hashing mechanism utilized for registered accounts. This flaw can allow unauthenticated attackers to measure response times, which can be exploited to enumerate valid usernames or email addresses. Such enumeration could lead to subsequent credential-stuffing, password-spraying, and phishing attacks. Users are advised to upgrade to version 2.4.1, where this issue has been addressed.
Affected Version(s)
server < 2.4.1
