CVE-2026-84699 Details
Description
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
An authentication bypass vulnerability has been identified in Team Password Manager versions prior to 14.184.308. The issue arises in the local account password reset process, where the application fails to properly enforce authentication requirements. This flaw allows unauthenticated attackers to reset passwords for local accounts and gain unauthorized access by authenticating as those users.
Users are advised to update Team Password Manager to version 14.184.308 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://teampasswordmanager.com/ | [email protected] | ProductVendor |
| https://teampasswordmanager.com/blog/chrome-extension-6.42.27-tpm-14.184.308/ | [email protected] | Release NotesVendor |
| https://teampasswordmanager.com/docs/changelog/ | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/team-password-manager-before-14.184.308-authentication-bypass-in-password-reset | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Team Password Manager | >= 0, < 14.184.308 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion