CVE-2026-84699 PUBLISHED

Team Password Manager before 14.184.308 Authentication Bypass in Password Reset

Assigner: VulnCheck
Reserved: 01.09.2026 Published: 02.09.2026 Updated: 02.09.2026

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Team Password Manager
Product Team Password Manager
Versions Default: unaffected
  • affected from 0 to 14.184.308 (excl.)

Credits

  • Aidan Stansfield finder

References

Problem Types

  • Weak Password Recovery Mechanism for Forgotten Password CWE