CVE-2026-84699 affects Team Password Manager versions before 14.184.308, where the local account password reset flow fails to enforce authentication requirements. This critical flaw allows unauthenticated attackers to reset passwords for local accounts without any prior authentication. Once reset, attackers can log in as those users and gain unauthorized access to managed passwords and sensitive data. The vulnerability is classified as an authentication bypass in the password reset mechanism. A patch has been released in version 14.184.308, which also includes an updated Chrome extension (6.42.27). Organizations using Team Password Manager are strongly advised to upgrade immediately. The vulnerability was disclosed via NVD and VulnCheck advisories. Given that password managers store highly sensitive credentials, exploitation could have severe downstream consequences.