Incorrect authorization in TeamPass - #VU151666
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose restricted passwords.
The vulnerability exists due to incorrect authorization in the copy_folder function when copying folders containing per-item restricted items. A remote user can copy items that they are restricted from viewing and obtain readable unrestricted copies.
The copied items do not retain the original per-item user or role restrictions.