Authorization bypass through user-controlled key in TeamPass - #VU151646

 

Authorization bypass through user-controlled key in TeamPass - #VU151646

Published: September 22, 2026


Vulnerability identifier: #VU151646
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose item metadata from folders they are not authorized to access.

The vulnerability exists due to improper access control in the do_items_list_in_folder AJAX action when requesting later pages of results for a folder. A remote user can submit a crafted pagination request with a user-controlled folder identifier and pagination state to disclose item metadata from unauthorized folders.

Encrypted passwords are not returned by the affected query, and cleartext passwords are not directly disclosed.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.1.5

External References

Related Security Bulletins