Junglewise Threat Intelligence

CVE-2026-84699: Team Password Manager authentication bypass in password reset

CVE-2026-84699 · Severity: critical · CVSS 9.1 · Published 2026-09-02

Executive brief

Team Password Manager is a self-hosted password management application used by teams to securely store and share credentials. A critical authentication flaw in the local account password reset feature allows attackers to reset user passwords without authentication, enabling unauthorized account access and full compromise of stored passwords.

Technical details

The vulnerability is an authentication bypass in the local account password reset flow that fails to enforce proper authentication requirements. Unauthenticated attackers can invoke the password reset mechanism to change passwords for existing local user accounts, then authenticate as those users to gain full access to the application and all stored credentials. The attack requires no special privileges, user interaction, or credentials—network access to the password reset endpoint is sufficient. This was patched in version 14.184.308 as documented in the release notes, which explicitly list "Fixes for vulnerabilities in the user password reset functionality" as part of the security improvements.

Affected products

  • Team Password Manager Team Password Manager before 14.184.308

Timeline

  • 2026-09-02: disclosed
  • 2026-03-15: patched: Version 14.184.308 released with fixes for password reset vulnerabilities

References