Incorrect authorization in TeamPass - #VU151667

 

Incorrect authorization in TeamPass - #VU151667

Published: September 22, 2026


Vulnerability identifier: #VU151667
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify or move items without authorization.

The vulnerability exists due to improper authorization in the update_item function in app/sources/items.queries.php when processing item edit requests. A remote user can submit an item update request that specifies a destination folder where they have write access to modify or move items without authorization.

Exploitation requires access to the item's source folder and write access to the destination folder.


Affected software

TeamPass

Remediation

Install security update from vendor's website.

TeamPass - update to 3.2.2.5

External References

Related Security Bulletins