{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/team-password-manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:teampasswordmanager:team_password_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-84699"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Team Password Manager (\u003c 14.184.308)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","web-application-security","credential-theft"],"_cs_type":"advisory","_cs_vendors":["Team Password Manager"],"content_html":"\u003cp\u003eTeam Password Manager versions prior to 14.184.308 are affected by a high-severity authentication bypass vulnerability, tracked as CVE-2026-84699. This flaw exists within the application's local account password reset mechanism, where the software fails to properly enforce authentication requirements. An unauthenticated remote attacker can exploit this weakness by submitting crafted requests to the password reset endpoint, effectively resetting the password for any local user account without knowing the current credentials. Successful exploitation results in complete account takeover, granting the attacker unauthorized access to sensitive stored credentials and administrative functions within the platform. Given the role of Team Password Manager in securing organization-wide secrets, this vulnerability presents a critical risk for credential exfiltration and lateral movement.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-84699 allows an unauthenticated attacker to gain full control over local user accounts. In an enterprise environment, this leads to the compromise of the organization's master password repository, resulting in the exfiltration of all stored credentials, potential unauthorized access to downstream systems, and the total loss of confidentiality regarding the organization's secrets management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Team Password Manager to version 14.184.308 or later immediately to address CVE-2026-84699.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests targeting the local account password reset endpoint.\u003c/li\u003e\n\u003cli\u003eAudit all local user accounts for unexpected password changes or unusual login activity originating from unrecognized IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T03:10:24Z","date_published":"2026-09-02T03:10:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-02-team-password-manager-auth-bypass/","summary":"Team Password Manager versions prior to 14.184.308 contain a critical authentication bypass vulnerability in the local account password reset workflow that allows unauthenticated attackers to perform account takeovers.","title":"Authentication Bypass in Team Password Manager via Password Reset Flow","url":"https://feed.craftedsignal.io/briefs/2026-09-02-team-password-manager-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Team Password Manager","version":"https://jsonfeed.org/version/1.1"}