Authorization bypass through user-controlled key in TeamPass - #VU140730
Published: August 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through user-controlled key in app/sources/downloadFile.php when handling file-download requests in the pathIsFiles=1 branch. A remote user can supply a valid fileid for an accessible file while setting name to another file in the files folder to disclose sensitive information.
The issue is limited to files within the configured files folder, and exploitation requires knowledge or guessing of a target filename.