CRITICALVulnerability

CVE-2026-84699

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

Properties

severity
CRITICAL
score
9.1
cve_id
CVE-2026-84699
signal_observed_at
2026-09-23T22:44:43+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-09-02T01:17:24.990
last_modified
2026-09-23T17:17:43.853

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Weak Password Recovery Mechanism for Forgotten Password

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84699 — Ninja Signal Threat Intelligence | Ninja Signal