External risk intelligence

Team Password Manager Authentication Bypass in Local Password Reset

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-84699

Team Password Manager is a web-based application designed for centralized password management. By nature, such systems are typically deployed as public-facing or externally accessible web services to facilitate access for users, making the authentication and password reset flows directly reachable over the internet.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

Team Password Manager has a vulnerability that allows unauthenticated attackers to reset local account passwords, potentially granting them unauthorized access to user accounts. This issue affects the password reset process within the application. The main concern is confirming relevance and exposure.

  • Attackers can reset passwords without logging in.
  • Protects sensitive credentials stored in the manager.
  • Verify if this password manager is in use.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication by exploiting a flaw in the local account password reset process. This allows them to gain unauthorized access to user accounts.

  • No prior authentication required.
  • Reset local account passwords.
  • Unauthorized access to accounts.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could reset local account passwords, allowing them to authenticate as other users and gain unauthorized access to the system.

  • Local account passwords could be compromised.
  • Attackers could reset passwords without authentication.
  • Unauthorized access to the system may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Team Password Manager, a self-hosted password management solution. Application owners and infrastructure teams are likely responsible for managing and securing this software. The immediate priority is to identify all instances of Team Password Manager, assess their reachability and business criticality, and then plan remediation based on the risk of unauthorized access.

  • Application owners must own this issue.
  • Verify Team Password Manager instances and reachability.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Team Password Manager?

Team Password Manager is a self-hosted, web-based platform that organizations use to store, organize, and share sensitive credentials. It acts as a central vault, allowing teams to manage access to various services securely from one application.

How does CVE-2026-84699 work?

This vulnerability is classified as CWE-640, which refers to a failure to maintain password-related security state. Specifically, the application does not properly verify identity during its local account password reset workflow, allowing an attacker to change a user's password without having the original credentials.

Do I need to be logged in to trigger this?

No. The flaw exists in a process that handles requests before a user session is established. Because the system fails to enforce authentication requirements at this specific step, no prior access or account privileges are needed to initiate the malicious reset.

Is my Team Password Manager instance at risk?

According to Halo Surface Signal, this software is typically deployed as a web service accessible over the internet to support remote team members. If your instance is reachable via a public network, it is exposed to this vulnerability, as attackers do not need to be on your local network to reach the password reset path.

When should I update my software?

You should prioritize updating immediately if you run any version prior to 14.184.308. Verify your current version, determine if it is internet-facing, and coordinate with your team to apply the vendor's provided update to close the authentication gap.

References