CVE-2026-87816
Deferred Deferred - Pending Action

PasswordPusher Time-of-Check-to-Time-of-Use Race Condition Bypass

Vulnerability report for CVE-2026-87816, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is incremented and the push expires.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
passwordpusher passwordpusher to 2.11.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PasswordPusher before version 2.11.1 has a race condition in its view limit enforcement. This allows attackers to bypass the one-time secret expiration after a set number of views by sending multiple concurrent requests. The flaw occurs because the system checks the view limit before incrementing it, creating a window where the secret remains accessible.

Detection Guidance

To detect this vulnerability, monitor for unusual concurrent requests to the PasswordPusher show endpoint. Check logs for multiple rapid accesses to the same secret URL within a short timeframe. Use network monitoring tools to identify repeated requests to the same resource before expiration.

Impact Analysis

If you use PasswordPusher versions before 2.11.1, sensitive one-time secrets could be accessed more times than intended. Attackers might retrieve confidential data meant to be viewed only once, leading to data leaks or unauthorized access to information.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strict access controls and data protection, such as GDPR's data minimization or HIPAA's safeguards for protected health information. Unauthorized access to one-time secrets may result in non-compliance penalties.

Mitigation Strategies

Immediately upgrade PasswordPusher to version 2.11.1 or later to address the race condition. If upgrading is not possible, implement rate limiting on the show endpoint to prevent concurrent requests. Review logs for any signs of exploitation and revoke potentially exposed secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87816. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart