AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-22T13:16:40.110Z and has not been modified since then. The NVD entry is currently 6.9 MEDIUM. The vulnerability affects PasswordPusher versions v1.45.11 through v2.9.5; fixed in v2.9.6. Anonymous push deletion possible due to improper authorization logic. Evidence limits suggest verifying affected d [truncated]
CVE-2026-41308 is a security issue in OSS PasswordPusher that allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. The issue has been patched in versions 1.69.3 and 2.4.2.