Missing Authorization in TeamPass - #VU140724

 

Missing Authorization in TeamPass - #VU140724

Published: August 2, 2026


Vulnerability identifier: #VU140724
CSH Severity: Medium
CVSS v4 BT: 5.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify folder ownership and cause a denial of access to organizational folders.

The vulnerability exists due to missing authorization in the update_folder action when handling folder update requests. A remote user can submit a specially crafted request with a victim folder id and a parentId pointing to their own personal folder to modify folder ownership and cause a denial of access to organizational folders.

Successful exploitation can move another team's credential subtree into the user's personal space, exposing plaintext metadata such as labels, logins, URLs, email addresses, and descriptions, while hiding the folder from the organization view.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.1.2

External References