Incorrect authorization in TeamPass - #VU151662
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose passwords and attachments from parent folders.
The vulnerability exists due to incorrect authorization in getCurrentAccessRights() when checking item access against a user's cached folder tree. A remote user can request items in blocked ancestor folders to disclose passwords and attachments from those folders.
Exploitation requires access to a subfolder whose blocked ancestor is present in the user's folder-tree cache.