SB2026080204 - Missing Authorization in TeamPass



SB2026080204 - Missing Authorization in TeamPass

Published: August 2, 2026

Security Bulletin ID SB2026080204
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to modify folder ownership and cause a denial of access to organizational folders.

The vulnerability exists due to missing authorization in the update_folder action when handling folder update requests. A remote user can submit a specially crafted request with a victim folder id and a parentId pointing to their own personal folder to modify folder ownership and cause a denial of access to organizational folders.

Successful exploitation can move another team's credential subtree into the user's personal space, exposing plaintext metadata such as labels, logins, URLs, email addresses, and descriptions, while hiding the folder from the organization view.


Remediation

Install update from vendor's website.