---
id: CVE-2026-84699
title: >-
  Team Password Manager before 14.184.308 fails to enforce authentication
  requirements in the local account password reset flow
summary: >-
  Team Password Manager before 14.184.308 fails to enforce authentication
  requirements in the local account password reset flow. Unauthenticated
  attackers can reset local account passwords and authenticate as those users to
  gain unauthoriz…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-640
published: '2026-09-02'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:43.853'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84699'
references:
  - url: 'https://teampasswordmanager.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://teampasswordmanager.com/blog/chrome-extension-6.42.27-tpm-14.184.308/
    label: disclosure@vulncheck.com
  - url: 'https://teampasswordmanager.com/docs/changelog/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/team-password-manager-before-14.184.308-authentication-bypass-in-password-reset
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00629
epssPercentile: 0.47919
ingestedAt: '2026-09-23T17:28:14.819Z'
---

## Overview

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
