Unverified Password Change in TeamPass - #VU151649

 

Unverified Password Change in TeamPass - #VU151649

Published: September 22, 2026


Vulnerability identifier: #VU151649
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-620
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over arbitrary local accounts.

The vulnerability exists due to an unverified password change in the initializeUserPassword() handler in sources/main.queries.php when processing pre-authentication password-reset requests for local non-LDAP accounts. A remote attacker can send a crafted password-reset request to take over arbitrary local accounts.

The password-reset operation regenerates the target user's encryption key pair, causing vault items encrypted with the old key to become unreadable.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.1.1

External References

Related Security Bulletins