Authentication Bypass in Team Password Manager by Team Password Manager
CVE-2026-84699

9.3CRITICAL

What is CVE-2026-84699?

The Team Password Manager product exhibits a vulnerability in its local account password reset flow prior to version 14.184.308. This flaw allows unauthenticated attackers to exploit the password reset mechanism, enabling them to reset passwords and gain unauthorized access to user accounts. As a result, attackers can effectively authenticate themselves as legitimate users, posing significant security risks to the affected systems.

Affected Version(s)

Team Password Manager 0 < 14.184.308

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aidan Stansfield
.