CRITICAL 9.3 NVD
CVE-2026-84699
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can res
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
References
- https://teampasswordmanager.com/
- https://teampasswordmanager.com/blog/chrome-extension-6.42.27-tpm-14.184.308/
- https://teampasswordmanager.com/docs/changelog/
- https://www.vulncheck.com/advisories/team-password-manager-before-14.184.308-authenticatio
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-02 via NVD.
Risk Timeline
CVE Disclosed2026-09-02 · -1 days ago
Remediation Resources
Analysis & PoC
teampasswordmanager.com/
vulnfeed aggregates 11552 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.