ZeroHour

CVE-2026-84699

niche

Unauthenticated Password Reset Bypass in Team Password Manager

CVSS 4.0
9.3 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-84699 is an authentication flaw (CWE-640) in Team Password Manager in which the local account password reset flow does not enforce its required authentication checks. An unauthenticated attacker who can reach the reset flow can reset the password of arbitrary local accounts and then authenticate as those users. This gives the attacker the privileges of the compromised account, and if an administrator account is targeted, potentially access to every password stored in the vault. Any deployment running Team Password Manager before 14.184.308 is affected, with greatest risk to instances reachable by untrusted or remote users. No public proof of concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.

What to do: Upgrade to Team Password Manager 14.184.308 or later. Until patched, limit access to the password reset endpoint (e.g., via reverse proxy or firewall rules) and keep the instance off the public internet where possible. Review authentication and password-reset logs for unexpected resets or logins, and rotate credentials for any account showing unexplained changes.

Affected
Team Password Managerall versions before 14.184.308
Estimated exposure
nicheunknown exact count; plausibly on the order of thousands of self-hosted instances — Team Password Manager is a niche self-hosted product typically deployed per organization and often kept on internal networks, and no public install-base counts or internet-exposure scan data exist, so this is a deployment-pattern estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

Weakness
CWE-640
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.