Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.7 Node.js & npm GHSA-274f-6w77-8qm9 CVE-2026-58271 GHSA-92cr-jxw4-5wjg CVE-2026-58269

Sync-in Server: Four Vulnerabilities Allow 2FA Bypass, Brute-Force, Username Enumeration, and Denial of Service

Sync-in Server, an open-source file storage and sync platform, contains four distinct vulnerabilities disclosed together: a complete 2FA bypass via the token endpoint, a TOTP brute-force flaw that can also disable MFA, a regex denial-of-service bug, and a timing-based username enumeration issue. Three are fixed in version 2.4.0; the fourth requires version 2.4.1.

AI summary

Sync-in Server, an open-source platform for file storage, sharing, collaboration, and syncing, is affected by four separate vulnerabilities disclosed around the same time. They range from a complete authentication bypass of two-factor authentication (2FA) to a denial-of-service condition affecting the whole server, and a username enumeration weakness. Three of the four issues are fixed in version 2.4.0; the fourth, an incomplete fix of a prior timing issue, requires version 2.4.1. Site operators running @sync-in/server should review each issue below and update accordingly.

What happened

Four vulnerabilities were disclosed in Sync-in Server (@sync-in/server, npm package): 1. CVE-2026-58269 (GHSA-92cr-jxw4-5wjg) — A complete 2FA bypass. The `POST /api/auth/token` endpoint authenticates with username and password only, then issues full access and refresh JWTs via `getTokens()` without checking whether the account has TOTP 2FA enabled. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by checking `user.twoFaEnabled`, but the token endpoint does not. 2. CVE-2026-58271 (GHSA-274f-6w77-8qm9) — A TOTP brute-force flaw in the desktop sync client registration endpoint (`POST /api/app/sync/register`). On a failed TOTP attempt, the internal `updateAccesses()` function hits a freeze branch that writes the `passwordAttempts` counter back unchanged, so it never reaches the configured maximum (`USER_MAX_PASSWORD_ATTEMPTS`, 10) and the lockout never triggers. A successful guess returns a client token pair that can be exchanged for a full JWT via `POST /api/app/sync/auth/cookie`. With a valid code, an attacker could also call `POST /api/auth/2fa/disable` to permanently remove MFA from the account. 3. CVE-2026-58270 (GHSA-jx63-h26r-8cph) — A regular expression denial-of-service (ReDoS). The sync diff endpoint compiles a user-supplied string directly into a `RegExp` without complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. 4. CVE-2026-58272 (GHSA-29hq-23m2-2j47) — An observable timing discrepancy in the login endpoint. Authentication attempts for nonexistent accounts return without performing the bcrypt comparison used for existing accounts, allowing an unauthenticated attacker to measure response times and enumerate valid usernames or email addresses. This advisory is described as an incomplete fix of a prior timing-attack issue.

Technical cause

Each issue stems from a different root cause: CVE-2026-58269 is an alternate-path authentication bypass (CWE-288) where the token-issuing code path omits the 2FA check present elsewhere in the code. CVE-2026-58271 is an improper restriction of excessive authentication attempts (CWE-307) caused by a 'freeze branch' in the attempt-counting logic that writes back the attempt counter unchanged instead of incrementing it. CVE-2026-58270 is an inefficient regular expression complexity issue (CWE-1333) from compiling untrusted user input directly into a RegExp without validation. CVE-2026-58272 is an observable timing discrepancy (CWE-208) where the code path for nonexistent accounts skips the bcrypt comparison performed for existing accounts, creating a measurable timing difference.

Why it matters

These issues target the authentication layer and overall availability of Sync-in Server. CVE-2026-58269 allows an attacker who has already obtained valid credentials (stolen or phished) to fully bypass 2FA in a single request, gaining full account access. CVE-2026-58271 compounds this: it enables brute-forcing of the TOTP code with no effective lockout, and a successful guess allows permanent removal of 2FA from the account via the disable endpoint, effectively eliminating MFA protection going forward. CVE-2026-58270 is a service-wide denial-of-service: a single malicious request can make the server unresponsive to all users until manually restarted. CVE-2026-58272 lowers the bar for subsequent credential-stuffing or password-spraying attacks by letting an unauthenticated attacker confirm which usernames or email addresses are valid.

Affected versions

@sync-in/server: CVE-2026-58269, CVE-2026-58271, and CVE-2026-58270 affect versions up to and including 2.3.0, fixed in 2.4.0. CVE-2026-58272 affects versions up to and including 2.4.0, fixed in 2.4.1.

Fixes and mitigation

Version 2.4.0 of @sync-in/server patches the 2FA bypass (CVE-2026-58269), the TOTP brute-force/lockout issue (CVE-2026-58271), and the ReDoS issue (CVE-2026-58270). Version 2.4.1 additionally patches the timing-based username enumeration issue (CVE-2026-58272), which was not fully addressed by a prior fix. Operators should update directly to 2.4.1 to receive all four fixes.

Recommended action

Update @sync-in/server to version 2.4.1 as soon as possible to apply all available patches. If an immediate update is not possible, treat the deployment as having unreliable 2FA enforcement and monitor for unusual account access, repeated TOTP submission attempts, and signs of service disruption. After updating, consider reviewing accounts for any 2FA settings that may have been altered during the affected period.

PatchBriefing score

4.7 / 10 · Medium

Official CVSS: 8.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Why this score

The four issues carry different severity ratings based on their CVSS scores: CVE-2026-58269 (2FA bypass) scores 8.1, reflecting high confidentiality and integrity impact exploitable with low complexity by an attacker who already holds valid low-privilege credentials. CVE-2026-58271 (TOTP brute-force) scores 6.8, with high attack complexity offsetting its high confidentiality/integrity impact. CVE-2026-58270 (ReDoS) scores 6.5, reflecting a high availability impact with no confidentiality or integrity loss. CVE-2026-58272 (timing enumeration) scores 5.3, the lowest of the four, as it only leaks limited confidentiality information (valid usernames) and requires no authentication or privileges to exploit. None of the four has a known public exploit or confirmed active exploitation, and no EPSS percentile data was available to further inform likelihood for CVE-2026-58269 or CVE-2026-58271 at the time of this writing; the available EPSS scores for the other two are low.

Affected versions

@sync-in/server <= 2.3.0
vulnerable
≥ 2.4.0
patched
@sync-in/server <= 2.3.0
vulnerable
≥ 2.4.0
patched
@sync-in/server <= 2.3.0
vulnerable
≥ 2.4.0
patched
@sync-in/server <= 2.4.0
vulnerable
≥ 2.4.1
patched

Reported fixes

Version 2.4.0 of @sync-in/server patches the 2FA bypass (CVE-2026-58269), the TOTP brute-force/lockout issue (CVE-2026-58271), and the ReDoS issue (CVE-2026-58270). Version 2.4.1 additionally patches the timing-based username enumeration issue (CVE-2026-58272), which was not fully addressed by a prior fix. Operators should update directly to 2.4.1 to receive all four fixes.

How this was built

8 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • GitHub Advisory Database database
  • GitHub Advisory Database database
  • GitHub Advisory Database database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Sync-in Server: Four Vulnerabilities Allow 2FA Bypass, Brute-Force, Username Enumeration, and Denial of Service
1 article · 8 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email