PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass
CVE-2026-62382
Verified
Description
PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials.
Severity
Medium
CVSS Score
6.9
Exploit Probability
1%
Affected Product
passwordpusher
Published Date
September 15, 2026
Template Author
dhiyaneshdk
CVE-2026-62382.yaml
6.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVE ID:
cve-2026-62382
CWE ID:
cwe-863
Remediation Steps
Upgrade PasswordPusher to v2.9.6 or later.