CVE-2026-84699
Received Received - Intake

Unauthenticated Password Reset in Team Password Manager

Vulnerability report for CVE-2026-84699, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: VulnCheck

Description

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
teampasswordmanager team_password_manager to 14.184.308 (exc)
team_password_manager team_password_manager to 14.184.308 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Team Password Manager before version 14.184.308 has a flaw in its local account password reset process. Attackers can reset passwords without authentication and gain unauthorized access to user accounts.

Detection Guidance

Check Team Password Manager version with: docker inspect <container_name> | grep VERSION or check the web interface footer. Versions before 14.184.308 are vulnerable. Monitor for unauthorized password resets or logins from local accounts.

Impact Analysis

Unauthenticated attackers could reset passwords for local accounts and access sensitive data managed by Team Password Manager. This could lead to data breaches, unauthorized actions, or full system compromise depending on user permissions.

Compliance Impact

This vulnerability could violate compliance requirements for data protection and access control, such as GDPR's integrity and confidentiality principles or HIPAA's access controls. Unauthorized access risks data exposure and non-compliance penalties.

Mitigation Strategies

Upgrade to Team Password Manager version 14.184.308 or later immediately. Review and reset all local account passwords. Enable two-factor authentication if not already active. Monitor logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84699. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart