Authorization bypass through user-controlled key in TeamPass - #VU151654

 

Authorization bypass through user-controlled key in TeamPass - #VU151654

Published: September 22, 2026


Vulnerability identifier: #VU151654
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to weaken credentials for privileged accounts outside their authorized folder scope.

The vulnerability exists due to missing authorization in the update_account_policy LAPR handler when processing account policy update requests. A remote user can assign a chosen rotation policy to an out-of-scope managed account to weaken credentials for privileged accounts outside their authorized folder scope.

Only installations with LAPR enabled are affected.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.2.1

External References

Related Security Bulletins