CVE-2026-3106
Received
Received - Intake
Blind XSS in Teampass Login Allows Admin Browser Exploitation
Publication date: 2026-03-31
Last updated on: 2026-04-07
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in the username field. As a result, arbitrary JavaScript code is automatically executed in the administrator's browser when viewing failed login entries, resulting in a blind XSS condition.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| teampass | teampass | From 3.1.5.16 (inc) to 3.1.5.24 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |