Improper privilege management in TeamPass - #VU140731

 

Improper privilege management in TeamPass - #VU140731

Published: August 2, 2026


Vulnerability identifier: #VU140731
CSH Severity: Medium
CVSS v4 BT: 6.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to folders or modify content outside their intended scope.

The vulnerability exists due to improper privilege management in the `add_one_role_to_user` context of the `save_user_change` action in `app/sources/users.queries.php` when handling a user-supplied role id. A remote user can submit a crafted request with an unauthorized role id to gain unauthorized access to folders or modify content outside their intended scope.

For regular users, the observed behavior was self-assignment to an existing role, and the resulting access depended on role membership, folder ACLs, and item sharekeys in the deployment.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.6

External References