CVE-2026-41308 Details
Description
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.
A vulnerability in OSS Password Pusher versions prior to 1.69.4 and 2.4.2 allows unauthenticated users to create file-type pushes through a generic JSON API endpoint. This issue arises under certain configurations where anonymous creation is permitted, bypassing the intended authentication requirements for file uploads. As a result, unauthorized individuals could exploit this flaw to consume resources such as storage and bandwidth.
Users are advised to upgrade to Password Pusher versions 1.69.4 or 2.4.2, where this vulnerability has been patched. If an immediate upgrade is not possible, 'allow_anonymous' can be set to false, file push capability can be restricted or disabled, untrusted API create traffic can be blocked at the edge, and unusual unauthenticated create activity can be monitored.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apnotic password pusher | < 1.69.3 >= 2.0.0, < 2.4.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Reanalysis | [email protected] |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |