PT-2026-57885 · Unknown · Password Pusher

·

CVE-2026-61458

·

Published

2026-07-13

·

Updated

2026-07-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PasswordPusher versions prior to 2.9.2
Description An issue exists where passphrase-protected pushes are susceptible to brute-force attacks. The 'POST /p/:token/access' endpoint lacks route-specific rate limiting and per-push lockout mechanisms. This allows an attacker who possesses a push token to systematically guess passphrases at a rate of 120 attempts per minute, potentially recovering short or dictionary-derived passphrases within hours or days.
Recommendations Update to version 2.9.2 or later.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61458
GHSA-59W3-H5V2-C4XW

Affected Products

Password Pusher