Description

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.

INFO

Published Date :

2026-05-08T14:30:37.513Z

Last Modified :

2026-05-08T14:30:37.513Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-41308 vulnerability.

Vendors Products
Pglombardo
  • Password Pusher

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact