Timing Discrepancy Vulnerability in Sync-in Server by Sync-in
CVE-2026-58272

5.3MEDIUM

Key Information:

Vendor

Sync-in

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-58272?

Sync-in Server, an open-source platform designed for file storage and collaboration, has a vulnerability affecting its login endpoint. Due to an observable timing discrepancy, authentication attempts made against nonexistent accounts return responses without engaging the bcrypt hashing mechanism utilized for registered accounts. This flaw can allow unauthenticated attackers to measure response times, which can be exploited to enumerate valid usernames or email addresses. Such enumeration could lead to subsequent credential-stuffing, password-spraying, and phishing attacks. Users are advised to upgrade to version 2.4.1, where this issue has been addressed.

Affected Version(s)

server < 2.4.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.