CVE-2026-84699: Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
Published Sep 2, 2026
·Updated
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Affected Software
1 affected component
Team Password Manager<14.184.308
Event History
Sep 2, 2026
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Deployments running Team Password Manager versions before 14.184.308 are affected. The issue concerns the local account password reset flow.
2
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They can reset a local account password and then authenticate as that user.
3
What is the impact after successful exploitation?
Successful exploitation grants unauthorized access as the local account whose password was reset. The reported impact includes high confidentiality and integrity impact.