Authorization bypass through user-controlled key in TeamPass - #VU151653
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the delta-sync endpoint GET /api/v1/item/changes when processing item change requests from callers with no accessible folders. A remote user can request item changes to disclose item change metadata outside their authorization scope.
Exposed metadata is limited to removed-entry item identifiers, revisions, and reasons; item labels, passwords, and custom fields are not disclosed.