PT-2026-37110 · Unknown · @Sync-In/Server

Ppfeister

·

Published

2026-04-15

·

Updated

2026-05-12

·

CVE-2026-41161

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sync-in Server versions prior to 2.2.0
Description A logic flaw in the "/api/auth/login" endpoint allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This timing discrepancy occurs because the application responds faster when a username does not exist compared to when a valid username is provided, as the backend short-circuits the process when no matching user is found.
Recommendations Update to version 2.2.0.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-41161
GHSA-43FJ-QP3H-HRH5

Affected Products

@Sync-In/Server