LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-84699

Published
CVSS9.1
Severitycritical
WeaknessCWE-640
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-84699

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-84699.