logo

Passwordstate dev urges users to patch auth bypass vulnerability

ID: e04e43de-7d22-5c12-a457-8d28f98c3773

STIX ID: report--e04e43de-7d22-5c12-a457-8d28f98c3773

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-08-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Click Studios released Passwordstate 9.9 Build 9972 to fix a high-severity authentication bypass that can let an attacker use a crafted URL on the Emergency Access page to access the administration section; a partial workaround (restricting Emergency Access allowed IPs) is available but upgrading is strongly recommended. The report also recalls a 2021 supply-chain compromise that distributed the Moserpass infostealer and may have resulted in harvested password records.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.