Vendor Homepageproduct
http://www.syncbreeze.com/ CVE-2020-36946
HIGH
SyncBreeze 10.0.28 - 'login' Denial of Service
Record summary
CVE-2020-36946 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SyncBreezeBrowse Flexense Ltd. / SyncBreeze | CVE List | 10.0.28 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSyncBreeze 10.0.28 - 'login' Denial of Service (Poc)ExploitDB exploitby Ahmed ElkhressyNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36946 ExploitDB-49291exploit
https://www.exploit-db.com/exploits/49291 VulnCheck Advisory: SyncBreeze 10.0.28 - 'login' Denial of ServiceThird-party advisory
https://www.vulncheck.com/advisories/syncbreeze-login-denial-of-service