Story perspectives
Passwordstate Urges Urgent Update to Fix Critical Vulnerability
8/29/2025
34 6
1 of 1
Story summary
- Passwordstate, an enterprise password manager, advises users to urgently update to fix a critical vulnerability allowing unauthorized vault access.
- The vulnerability involves an authentication bypass through a malicious URL on the Emergency Access page.
- The issue was resolved in Passwordstate version 9.9, released on August 28, 2025, but lacks a CVE identifier.
- This update follows a prior supply chain breach affecting the software's update mechanism.
