CVE-2026-84699
Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
| CWE | CWE-640 |
| Vendor | team password manager |
| Product | team password manager |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for team password manager team password manager
Be the first to know when new critical vulnerabilities affecting team password manager team password manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Team Password Manager / Team Password Manager
0 < 14.184.308
References
teampasswordmanager.com: https://teampasswordmanager.com/ teampasswordmanager.com: https://teampasswordmanager.com/blog/chrome-extension-6.42.27-tpm-14.184.308/ teampasswordmanager.com: https://teampasswordmanager.com/docs/changelog/ vulncheck.com: https://www.vulncheck.com/advisories/team-password-manager-before-14.184.308-authentication-bypass-in-password-reset
Credits
Aidan Stansfield