Authorization bypass through user-controlled key in TeamPass - #VU151654
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to weaken credentials for privileged accounts outside their authorized folder scope.
The vulnerability exists due to missing authorization in the update_account_policy LAPR handler when processing account policy update requests. A remote user can assign a chosen rotation policy to an out-of-scope managed account to weaken credentials for privileged accounts outside their authorized folder scope.
Only installations with LAPR enabled are affected.