Skip to content
archivevulnerability · 22 Sep 2026 · 14:46 UTC

GHSA-92cr-jxw4-5wjg: Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`

VULNCVE-2026-58269source · GTH
HIGHHigh-risk vulnerability — CVSS 8.1

last 60 dispatches · spectrum

**Affected component:** Sync-in Server v2.3.0, `POST /api/auth/token` (`auth.controller.ts:50-55`). **Required attacker capability:** Valid username and password for a 2FA-enabled account. ## Summary `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns unrestricted Bearer access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker who already knows valid credentials for a 2FA-enabled account can bypass 2FA in a single request. …

CVE · detail
grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected