Missing Authentication for Critical Function in TeamPass - #VU151651
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication for a critical function in the generateBugReport() handler in sources/main.queries.php when processing crafted POST requests. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation depends on the separately reported pre-authentication dispatch bypass.