CVE-2026-84699
nicheUnauthenticated Password Reset Bypass in Team Password Manager
CVE-2026-84699 is an authentication flaw (CWE-640) in Team Password Manager in which the local account password reset flow does not enforce its required authentication checks. An unauthenticated attacker who can reach the reset flow can reset the password of arbitrary local accounts and then authenticate as those users. This gives the attacker the privileges of the compromised account, and if an administrator account is targeted, potentially access to every password stored in the vault. Any deployment running Team Password Manager before 14.184.308 is affected, with greatest risk to instances reachable by untrusted or remote users. No public proof of concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days.
What to do: Upgrade to Team Password Manager 14.184.308 or later. Until patched, limit access to the password reset endpoint (e.g., via reverse proxy or firewall rules) and keep the instance off the public internet where possible. Review authentication and password-reset logs for unexpected resets or logins, and rotate credentials for any account showing unexplained changes.
| Team Password Manager | all versions before 14.184.308 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
- Weakness
- CWE-640
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.