CVE-2026-84699CWE-640

CVE-2026-84699

Critical · published September 2, 2026

CVSS v3.1
9.1
EPSS
0%
Percentile
29.8
In the wild
Unconfirmed
What it is

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00367 · 29.8th percentile
Weakness
CWE-640 · Weak Password Recovery Mechanism for Forgotten Password
Published
2026-09-02T05:17Z
References (4)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 02 SEP 00:37Z
    Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
    cvelistv5