Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 14, 2026
PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint
CVE-2026-61458
Description
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense, making short or dictionary-derived passphrases practically recoverable within hours or days.
Affected products
2- Range: <2.9.2
- Range: <2.9.2
Patches
Vulnerability mechanics
References
2- github.com/pglombardo/PasswordPusher/security/advisories/GHSA-59w3-h5v2-c4xwmitrevendor-advisory
- www.vulncheck.com/advisories/passwordpusher-passphrase-brute-force-via-unthrottled-endpointmitrethird-party-advisory
News mentions
0No linked articles in our index yet.