Authorization bypass through user-controlled key in TeamPass - #VU151647

 

Authorization bypass through user-controlled key in TeamPass - #VU151647

Published: September 22, 2026


Vulnerability identifier: #VU151647
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to copy items into folders they are not authorized to access.

The vulnerability exists due to authorization bypass through a user-controlled key in the `copy_item` action in `items.queries.php` when processing copy requests containing a destination folder identifier. A remote user can submit a copy request specifying a restricted destination folder to copy an accessible item into that folder.

Exploitation requires write access to at least one shared folder.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.1.5

External References

Related Security Bulletins