Authorization bypass through user-controlled key in TeamPass - #VU151655

 

Authorization bypass through user-controlled key in TeamPass - #VU151655

Published: September 22, 2026


Vulnerability identifier: #VU151655
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to remove managed accounts outside their authorized folder scope from credential rotation.

The vulnerability exists due to missing authorization in the delete_account LAPR handler when processing account deletion requests. A remote user can submit a deletion request for an out-of-scope managed account to remove managed accounts outside their authorized folder scope from credential rotation.

Only installations with LAPR enabled are affected.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.2.1

External References

Related Security Bulletins