Missing Authorization in TeamPass - #VU140724
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote user to modify folder ownership and cause a denial of access to organizational folders.
The vulnerability exists due to missing authorization in the update_folder action when handling folder update requests. A remote user can submit a specially crafted request with a victim folder id and a parentId pointing to their own personal folder to modify folder ownership and cause a denial of access to organizational folders.
Successful exploitation can move another team's credential subtree into the user's personal space, exposing plaintext metadata such as labels, logins, URLs, email addresses, and descriptions, while hiding the folder from the organization view.