Observable discrepancy in TeamPass - #VU140735

 

Observable discrepancy in TeamPass - #VU140735

Published: August 2, 2026


Vulnerability identifier: #VU140735
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to enumerate valid usernames and verify guessed passwords for arbitrary accounts.

The vulnerability exists due to observable discrepancy and improper restriction of excessive authentication attempts in the ga_generate_qr handler in app/sources/main.queries.php when processing crafted unauthenticated requests for login enrollment. A remote attacker can send repeated specially crafted requests to enumerate valid usernames and verify guessed passwords for arbitrary accounts.

The responses differ for unknown usernames and wrong passwords, and this code path performs no brute-force accounting or lockout.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.6

External References