Authorization bypass through user-controlled key in TeamPass - #VU151647
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to copy items into folders they are not authorized to access.
The vulnerability exists due to authorization bypass through a user-controlled key in the `copy_item` action in `items.queries.php` when processing copy requests containing a destination folder identifier. A remote user can submit a copy request specifying a restricted destination folder to copy an accessible item into that folder.
Exploitation requires write access to at least one shared folder.