Incorrect Comparison in TeamPass - #VU140791

 

Incorrect Comparison in TeamPass - #VU140791

Published: August 3, 2026


Vulnerability identifier: #VU140791
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to incorrect comparison in app/sources/admin.queries.php when handling administrative action requests. A remote privileged user can send a specially crafted request to cause a denial of service.

The issue affects 13 administrative switch cases, and the outer page-access gate restricts access to admin users while the inverted inner check blocks those same users from executing the operations.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.0.0

External References

Related Security Bulletins