Improper Authentication in TeamPass - #VU140789

 

Improper Authentication in TeamPass - #VU140789

Published: August 3, 2026


Vulnerability identifier: #VU140789
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to authenticate as another user and take over that account.

The vulnerability exists due to improper authentication in app/sources/identify.php when processing a primary login request after an OAuth2 login flow. A remote user can submit a victim's username with an arbitrary password to authenticate as another user and take over that account.

Exploitation requires OAuth2 login to be enabled and the target account to use local or LDAP authentication. The issue can also permanently change the victim account's auth_type to oauth2.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.6

External References

Related Security Bulletins