OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-58269

HIGH · CVSS 8.1 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Sync-in Server platform, prior to version 2.4.0, is vulnerable due to its authentication mechanism that allows attackers to bypass two-factor authentication (2FA) using stolen credentials when accessing the `POST /api/auth/token` endpoint. This flaw can lead to unauthorized access, as it grants full access and refresh JWTs without verifying if 2FA is enabled for the account. Organizations using affected versions should prioritize upgrading to 2.4.0 to mitigate the risk of credential theft and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58269
Severity
HIGH
CVSS
8.1
EPSS
0.22%

Original NVD Description

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue.