Missing Authentication for Critical Function in TeamPass - #VU151661
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing authentication for a critical function in the public/sources/scheduler.php wrapper when handling HTTP requests to the scheduler endpoint. A remote attacker can invoke the scheduled-job dispatcher to cause a denial of service.
The accessible dispatcher can trigger only the instance's configured scheduled jobs.