Missing Authorization in TeamPass - #VU140726
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote user to bypass folder-based authorization and create items in unauthorized folders.
The vulnerability exists due to missing authorization in the CSV import pipeline when importing staged rows into an attacker-supplied folder id. A remote user can submit a crafted import request with an arbitrary folderId to bypass folder-based authorization and create items in unauthorized folders.
Exploitation requires access to /index.php?page=import with allow_import enabled and a staged CSV import operation.