Authorization bypass through user-controlled key in TeamPass - #VU140730

 

Authorization bypass through user-controlled key in TeamPass - #VU140730

Published: August 2, 2026


Vulnerability identifier: #VU140730
CSH Severity: Low
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through user-controlled key in app/sources/downloadFile.php when handling file-download requests in the pathIsFiles=1 branch. A remote user can supply a valid fileid for an accessible file while setting name to another file in the files folder to disclose sensitive information.

The issue is limited to files within the configured files folder, and exploitation requires knowledge or guessing of a target filename.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.6

External References