Incorrect authorization in TeamPass - #VU151664
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to modify folder contents in inaccessible personal or shared folder trees.
The vulnerability exists due to incorrect authorization in the copy_folder function when copying folders to an attacker-supplied destination folder. A remote user can specify an inaccessible destination folder to create folders and copy items into it.
Shared-folder exploitation requires that users can create folders or that the user has a role permitted to create folders.