CVE-2026-84699
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticat
CVSS
9.1
Crítico
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 2 sept 2026 · Última mod.: 2 sept 2026 · CWE-640
0.4%EPSS · 30 días0.4%
2026-09-022026-09-05
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
- teampasswordmanager.comhttps://teampasswordmanager.com/
- teampasswordmanager.comhttps://teampasswordmanager.com/blog/chrome-extension-6.42.27-tpm-14.184.308/
- teampasswordmanager.comhttps://teampasswordmanager.com/docs/changelog/
- www.vulncheck.comhttps://www.vulncheck.com/advisories/team-password-manager-before-14.184.308-authentication-bypass-in-password-reset
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-862606.5 MED—
———A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified password change. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.6hCVE-2026-824876.3 MED10.6%
——3A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.6dCVE-2026-801967.5 ALT35.2%
——11Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour window to log in as the user even after the legitimate user has changed their password.7dCVE-2026-196329.8 CRÍ53.4%
——16The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters stored in the translation dictionary table — enabling full administrator account takeover. This vulnerability is only exploitable when automatic string saving is enabled (the default setting) and the target administrator's profile locale is set to a published secondary language, as these conditions cause the password-reset URL to be persisted as a translatable string in the secondary-language dictionary table.12dCVE-2026-772649.8 CRÍ44.7%
——13The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly accessible OTP request, rather than only delivering it to the user's email address. This makes it possible for unauthenticated attackers to log in as any user on the site, including administrators, if they know that user's email address.14dCVE-2026-189639.1 CRÍ87.5%
——26A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.18d