CVE-2026-41161

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/05/2026
Last modified:
12/05/2026

Description

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This issue has been patched in version 2.2.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sync-in:sync-in_server:*:*:*:*:*:*:*:* 2.2.0 (excluding)