Authorization bypass through user-controlled key in TeamPass - #VU151655
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to remove managed accounts outside their authorized folder scope from credential rotation.
The vulnerability exists due to missing authorization in the delete_account LAPR handler when processing account deletion requests. A remote user can submit a deletion request for an out-of-scope managed account to remove managed accounts outside their authorized folder scope from credential rotation.
Only installations with LAPR enabled are affected.