Authorization bypass through user-controlled key in TeamPass - #VU151646
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose item metadata from folders they are not authorized to access.
The vulnerability exists due to improper access control in the do_items_list_in_folder AJAX action when requesting later pages of results for a folder. A remote user can submit a crafted pagination request with a user-controlled folder identifier and pagination state to disclose item metadata from unauthorized folders.
Encrypted passwords are not returned by the affected query, and cleartext passwords are not directly disclosed.