Key Exchange without Entity Authentication in TeamPass - #VU151656
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose privileged SSH credentials.
The vulnerability exists due to key exchange without entity authentication in LAPRSshService::connect() when connecting to managed endpoints over SSH. A remote attacker can intercept SSH traffic and impersonate a managed endpoint to disclose privileged SSH credentials.
Exploitation requires the ability to intercept traffic between the TeamPass server and a managed endpoint. Only installations with LAPR enabled are affected.