NewsSecurity Vulnerabilities

Critical Team Password Manager Vulnerability Allows Account Takeover (CVE-2026-84699)

A critical security vulnerability in Team Password Manager could allow unauthenticated attackers to take control of user accounts through the application’s password reset process.

Tracked as CVE-2026-84699, the flaw affects versions of Team Password Manager before 14.184.308. The vulnerability occurs because the local-account password reset process does not properly enforce authentication requirements.

An attacker does not need valid credentials or user interaction to exploit the issue. By resetting a local user’s password, an attacker could subsequently authenticate as that account and gain unauthorised access to information and functionality available to the compromised user.

The vulnerability has been rated Critical, receiving a CVSS 4.0 score of 9.3 and a CVSS 3.1 score of 9.1. It is classified as CWE-640 – Weak Password Recovery Mechanism for Forgotten Password.

Organisations running affected versions of Team Password Manager should upgrade to version 14.184.308 or later as soon as possible and review accounts and authentication activity for signs of unauthorised access.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.