CVE-2026-41161
EUVD-2026-2855108.05.2026, 14:16
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This issue has been patched in version 2.2.0.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.