Sceawere
Vulnerability Detail
CVE-2026-84699UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Password Reset Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 1d ago
- Vendor
- Team Password Manager
- Product
- Team Password Manager
- Attack Type
- Weak Password Recovery Mechanism for Forgotten Password
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-02T01:17:24.990Z",
"pubdate": "2026-09-02T01:17:24.990Z",
"executiveSummary": "Team Password Manager versions prior to 14.184.308 are susceptible to an authentication bypass vulnerability within the local account password reset mechanism.\nThe flaw stems from a failure to enforce mandatory authentication requirements during the password reset workflow.\nThis vulnerability allows unauthenticated, remote attackers to initiate and complete a password reset process for any local account, including administrative accounts.\nSuccessful exploitation results in full unauthorized access to the target account, compromising the confidentiality, integrity, and availability of all stored credentials within the Team Password Manager instance.\nThe risk is categorized as critical due to the ease of exploitation, requiring no prior authentication or administrative privileges to execute the attack.\nOrganizations using affected versions of Team Password Manager are at significant risk of unauthorized data exfiltration and complete system takeover.",
"technicalDetails": "The vulnerability resides within the local account password reset implementation of Team Password Manager. Analysis indicates that the application fails to validate the requester's identity before processing password modification requests.\nRoot cause: The server-side logic governing the password reset function lacks the necessary access control checks to verify that the user requesting a password change is either the owner of the account or an authorized administrator. By failing to integrate session validation or token-based verification within the reset flow, the application treats unauthenticated requests as legitimate operations.\nAttack Flow: An attacker can identify the password reset endpoint and interact with it directly via HTTP requests. Since the application does not enforce authentication, the attacker can submit a crafted request specifying a target username or account identifier to the vulnerable endpoint. The system then processes the request, allowing the attacker to set a new password for the specified local account without interacting with the legitimate account owner or providing prior credentials.\nExploitation Method: Exploitation is performed via network-based requests directed at the Team Password Manager instance. An attacker does not require elevated privileges or physical access to the server, as the vulnerability is exposed via the web interface accessible over the network.\nPost-Exploitation Impact: Once the password for a target account has been reset by the attacker, they can authenticate into the application as that user. If the targeted account has administrative privileges, the attacker gains full control over the application, including the ability to view all managed passwords, modify system settings, create new unauthorized accounts, or exfiltrate sensitive data stored within the vault.\nAffected Versions: All versions of Team Password Manager prior to 14.184.308 are confirmed to be vulnerable. The absence of strict authentication enforcement renders the standard reset security flow ineffective against malicious actors."
}