Authorization bypass through user-controlled key in TeamPass - #VU151657
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to gain root access to arbitrary enrolled Linux servers.
The vulnerability exists due to missing authorization in LAPR endpoint management operations when associating managed accounts with enrolled endpoints. A remote user can associate a managed account with an arbitrary endpoint and trigger a password rotation to gain root access to arbitrary enrolled Linux servers.
Only installations with LAPR enabled are affected.