Skip to content
Release history

What's new in Teampass 3.2

The 3.2 line rebuilt the cryptography, added the governance features auditors ask for, and closed a long list of security advisories. Here is what changed, release by release.

The short version

Five changes worth upgrading for

Linux password rotation

LAPR changes the passwords of local Linux accounts over SSH, agentless, from the item that stores them — pushing to the server first, then re-encrypting the vault entry.

Authenticated encryption

AES-256-GCM replaces AES-CBC, with random IVs, per-secret salts, 256-bit object keys, PBKDF2 at 600,000 iterations and HKDF-SHA256. Existing vaults migrate lazily, on first read.

Security Posture Dashboard

Weak, reused, breached and overdue credentials at a glance, a personal security score for every user, and quality indicators shown while editing an item.

Governance built in

Access recertification campaigns, rotation policy tracking, leaver risk detection, four-level data classification and CSV evidence export.

Secure Send

Share a credential with someone outside Teampass under an expiry, a view limit and an optional recipient passphrase.

Upgrading from 3.1 or earlier? New features are seeded disabled, and the hardened encryption format stays off until you turn it on — so an upgrade will not change behaviour under your users. Back up the database first, then enable features one at a time.

Release by release

Changelog

Condensed from the GitHub release notes. Advisory identifiers link to the published GitHub Security Advisory for that issue.

3.2.2.7

4 October 2026

Two advisories, private key recovery copies sealed against database dumps and MFA enforced for roles inherited from AD groups, plus folder deletion protection and Markdown and category browsing in the knowledge base.

Security

  • A database dump alone no longer reveals the users' private keys, whose recovery copy is now sealed with the instance key (GHSA-fv78-jwjv-pj25)
  • The LDAP bind password and the SMTP password are encrypted with the instance key and never sent back to the settings pages
  • The MFA role requirement also applies to roles inherited from AD groups, and saving the user form no longer turns them into manual roles (GHSA-6mg2-rh62-rr3g)
  • The Docker image logs request paths without their query string or Referer, so Secure Send link credentials stay out of its access log
  • The session cookie is marked Secure behind a trusted reverse proxy that terminates HTTPS

New

  • Administrators can protect a folder against accidental deletion, which also blocks deleting any parent folder containing it
  • A branded Secure Send recipient page, with an organisation name, the local custom logo and an opt-in sender name
  • A List / Categories switch on the knowledge base page
  • Markdown pasted into a knowledge base article is formatted, and an Edit as Markdown view sits next to the code view

Improved

  • A folder holding items used by LAPR can no longer be deleted or moved into a personal folder
  • A Secure Send deployment and hardening guide
  • The dead INSTALL_MODE=auto Docker option is removed, and the Docker Hub volume and backup instructions are fixed
  • Open sessions are closed while a database upgrade is pending
  • Polish is fully translated

Fixed

  • Key generation for a new account resumes in slices instead of failing at the task time limit on a large vault
  • The sharekeys repair restores the owner's key on personal items damaged by issue 5407
  • LDAP bind and SMTP passwords containing &, ', ", < or > are saved as typed instead of HTML-encoded
  • See log works for an account without any log
  • The file integrity check of the Docker image no longer reports three critical unknown files
  • Knowledge base articles keep their image sizes, merged cells and literal HTML code samples

Upgrade notes

  • Schema change and data migration, the upgrade wizard runs once on every installation and sign-in is closed until it has run
  • Database dumps taken before the upgrade still open the private keys and must be protected or destroyed
  • Returning to an older version after the upgrade is not supported
  • Users holding the MFA role only through an AD group are asked for MFA at their next sign-in
  • The Docker access log format changed, and INSTALL_MODE, ADMIN_EMAIL and ADMIN_PWD are no longer read
  • The sender name on Secure Send pages stays off on upgraded installations until an administrator enables it

3.2.2.6

1 October 2026

Three access-control advisories, folder rights enforced on item creation, and a reworked Secure Send with reveal confirmation, item snapshots and opt-in TOTP sharing.

Security

  • Creating, revealing and listing a Secure Send link require current access to the item, so a user can no longer share an item from a folder they cannot see or an item restricted to others (GHSA-chpj-3vff-555v)
  • The personal-items recovery dialog only acts on the signed-in user's own account (GHSA-6rq2-hf9c-cxh2)
  • Deleting an item deletes that item alone, instead of also deleting another item whose key was sent with the request (GHSA-ghj3-wppx-w8j3)
  • A read-only role can no longer create items in a folder or copy items into it, and delete buttons are hidden without the delete right
  • New installations lock an account after 10 failed logins instead of never, and the administrator dashboard warns while an existing installation still has no threshold
  • The Security posture scan only queries Have I Been Pwned when breach detection is enabled, and a replaced compromised password loses its breach badge

Secure Send

  • Recipients confirm on the page before the content is revealed, so a link scanner cannot consume a view, and view limits hold under concurrent requests
  • Item links share an encrypted snapshot of the item as it was when the link was created
  • Sharing the current TOTP code is an explicit option, unchecked by default, and the TOTP secret never reaches the browser
  • The public sharing address accepts a full HTTPS URL or a hostname, is validated on save, and is only used when the sender selects it
  • The sender form can no longer generate two links or copy a stale one, and follows the AdminLTE layout

New

  • A custom login background, and login logo and background images picked by file name from a dedicated public/assets/custom folder
  • A Configuration check panel on the LDAP settings page, whose test button now runs the real login code
  • A totp column in the CSV export, written as an otpauth URI for non-standard profiles
  • A per-role switch for the Security posture Fix shortcuts, which now only point to items the user may edit

Improved

  • A clear permission error when the configuration directory cannot be read, instead of the installer or a bare HTTP 500, and an installer that refuses a database already in use
  • The password show button of the item form is a toggle, remembered in the browser
  • Background tasks start on Windows without opening console windows
  • Scheduled backup report e-mails use a table layout in every shipped language
  • A rewritten security hardening guide and a new Security posture documentation page

Fixed

  • Accounts created on 3.0.x whose password holds special or accented characters can log in after the upgrade
  • Personal-items recovery after a key regeneration re-encrypts the items again
  • Saving a personal item created by another user no longer removes its owner's access
  • Personal items still encrypted with a 2.x salt key can be migrated again
  • Accented search terms find labels saved from the item form, and search results show accented characters instead of HTML entities
  • The KeePass import no longer stops on an entry without a title, and imports passwords containing & as written
  • Duo starts in one click when it is the only MFA method
  • The browser extension FQDN suggestion is a placeholder instead of a value that only looked saved
  • The Docker example environment file defaults to the latest image tag

Upgrade notes

  • Schema change, the upgrade wizard runs once on every installation
  • Set a lockout threshold if the administrator dashboard reports that failed logins never lock an account
  • Users with read-only access on a folder can no longer create items there
  • Secure Send recipients press a confirmation button, and requiring a passphrase or disabling notes now also applies to existing links
  • If the public sharing address is a short prefix, check the public route, new links always use HTTPS and keep the main URL's port and path
  • On Docker, mount individual branding files into public/assets/custom rather than the folder itself
  • Back up the database before upgrading

3.2.2.5

19 September 2026

Two access-control advisories on item moves and folder copies, individual password renewal periods, and a rebuilt Monitoring logs page.

Security

  • Copying a folder requires access to the target folder, and skips the items the user is restricted from and the subfolders they are denied (GHSA-q47m-rvr6-jqw7)
  • Moving an item through the REST API requires the delete right on the source folder and the edit right on the target (GHSA-q47m-rvr6-jqw7)
  • The item edit form checks the move rights on the item's own folder instead of the destination (GHSA-vxv5-cr34-5q7g)
  • Moving an item to a personal folder through the API removes the other users' keys, as the web move does

New

  • Individual password renewal periods on items, set by anyone who can edit them, with the shorter of the item and folder periods applying
  • The Renewal page moves to the user sidebar, with deadline icons in the item list and the applicable policy shown in folder banners, item forms and move confirmations

Improved

  • The Monitoring logs page is rebuilt around a single filter panel, and its purge deletes exactly the entries on screen
  • API authentication refusals name their cause in the log, while the answer sent to the client stays the same
  • Every user allowed to use extension tokens can list and revoke them
  • Selected values in multiple-choice fields are readable, with a 5:1 contrast
  • Rewritten browser extension documentation, with installation from the Chrome, Edge and Firefox stores

Fixed

  • Accented characters are no longer saved as HTML entities when client/server encryption is disabled
  • Active Directory groups are mapped to roles when the user DN attribute setting is left empty
  • Restoring a backup stored on S3 no longer fails with a Malformed UTF-8 data error
  • The e-mail test button reports SMTP failures instead of waiting forever, and failed messages stay queued
  • Clearing Knowledge Base logs without dates no longer deletes every matching entry
  • A user's log no longer shows entries recorded for an IP address such as 10.0.0.5

Upgrade notes

  • Schema change, the upgrade wizard runs once on every installation
  • The Renewal page leaves the administration area, administrators supervise renewals through the compliance reports
  • Users with the ND, NE or NDNE level on a folder can no longer move its items out, from the web or from the API
  • API item reads return renewal_period, and a move to a personal folder answers 422 while the item's keys are still being distributed
  • Back up the database before upgrading

3.2.2.4

12 September 2026

Two access-control advisories, idempotent item creation and deletion in the API, and a self-service trial of the browser extension licence.

Security

  • The REST API applies item-level restrictions, so a user excluded from an item can no longer read its password or its TOTP code, nor update or delete it (GHSA-gxc6-rgv6-wx99)
  • Item access is granted only for a folder of the user's own scope, closing a path where a grant on a subfolder gave read access to the passwords of its parent (GHSA-jr9q-x7pj-8qh9)
  • The API tag list is scoped to the items the caller can read, instead of returning the tags of every folder in the instance

New

  • Self-service trial of the browser extension licence, requested from the Licence tab of the API settings, with an offline path by e-mail, clipboard or QR code for an instance with no Internet access
  • Idempotent item creation and conditional deletion in the REST API, so a client that lost the response can retry without creating a second item
  • A search field in the LDAP synchronization user list

Improved

  • Twenty production dependencies refreshed, among them phpseclib 3.0.57, Guzzle 7.15.5, the Symfony 6.4.45 components and TCPDF 6.11.4
  • The Docker image applies the Alpine security updates at build time, and is rebuilt every week so an unchanged release keeps receiving them

Fixed

  • Monitoring logs honour the selected search column, and the Errors, Copy, Admin and Failed logins purges apply the selected account instead of deleting the entries of every account
  • A newly created folder appears in the Items tree without a manual refresh
  • Renaming, moving or changing the icon of a folder from the Items page no longer resets its special options and its renewal period, and a new subfolder inherits them from its parent
  • The background task log is written again, and two task handlers can no longer run at once
  • The file integrity check no longer warns about the background tasks lock file
  • The login form accepts one submission at a time
  • The admin dashboard no longer reports an enabled scheduled backup as missing, and the new version available notice stops showing after an upgrade

Upgrade notes

  • Schema change, the upgrade wizard runs once on every installation
  • Let running background tasks finish before replacing the files, the handler lock file is now kept instead of deleted
  • API clients no longer receive the items the caller is restricted from, and the tag list only covers readable items
  • Re-check the special options and the renewal period of the folders you renamed or moved from the Items page
  • Back up the database before upgrading

3.2.2.3

4 September 2026

Hotfix — the administration page shipped inert in 3.2.2.2, killed by a JavaScript syntax error.

Fixed

  • The administration page works again, a template emitted two declarations on a single output line and the whole script block failed to parse
  • The regression guard meant to catch that shape no longer misses a declaration sitting at column zero

Upgrade notes

  • No schema change of its own, an installation already running 3.2.2.2 is not sent back through the upgrade wizard

3.2.2.2

4 September 2026

An unauthenticated entry point to the background scheduler, a leftover installation table holding the administrator password in clear text, and a Docker upgrade path that could leave a container unable to log in.

Security

  • The background scheduler wrapper sitting in the web root is removed, and the scheduler itself refuses any invocation that does not come from a command line (GHSA-fpv9-jxph-qg96)
  • The temporary installation table holding the administrator password in clear text is now really dropped, by the installer and by the upgrade
  • Client-side sanitization helpers rewritten after CodeQL findings, among them an entity decoder that turned a stored escape back into a live quote

Improved

  • The admin dashboard information card becomes Actions required, and disappears entirely when there is nothing to act on
  • Five dismissible getting-started recommendations for a fresh installation
  • The file integrity manifest no longer lists the development metadata vendored inside dependencies

Fixed

  • A Docker container no longer skips a patch migration and ends up unable to log in
  • The command palette returns items again, its restriction clause targeted the wrong table alias

Upgrade notes

  • Data migration without any table alteration, the upgrade wizard runs once on every installation
  • A crontab calling the scheduler over HTTP now gets a 404, the supported invocation has always been the command line one
  • Back up the database before upgrading

3.2.2.1

3 September 2026

Seven security advisories, four of them in LAPR, plus file integrity diagnostics, folder search and a Docker upgrade path that no longer leaves databases half-migrated.

Security

  • LAPR endpoints are now scoped to the caller, so an operator can no longer attach an account to an endpoint whose SSH credential they cannot read (GHSA-mq4w-p2gw-pqp4)
  • The SSH host key is verified before the credential is transmitted, closing a window where a man-in-the-middle received the plaintext password of a privileged account (GHSA-h25r-8cc9-2cg8)
  • Deleting a managed account and changing its rotation policy now check folder scope, blocking a weak policy from being pushed to a privileged Linux account (GHSA-v7hq-28rv-qh3p)
  • The API change feed no longer discloses instance-wide item ids and activity to a caller holding no folder rights (GHSA-9823-p8pg-rfm4)
  • The item history detail is encoded where it is rendered, closing a stored cross-site scripting reachable from any edited field (GHSA-mwxw-gg4p-8xpc)
  • The item login is rendered as text rather than markup (GHSA-47xg-w656-j4v4)
  • Two entity-decoding helpers no longer build a live DOM node while decoding (GHSA-5vf9-rxqv-g8wp)
  • The command palette applies item-level restrictions, so it no longer returns items the user cannot open

New

  • File integrity and permission diagnostics in System Health, replacing the old unknown-files counter and its web deletion workflow with a read-only report
  • A command-line integrity script for environments reachable only over SSH
  • Folder results, a folder filter and a reset control on the search page
  • Periodic checks of enrolled LAPR endpoints, and a pause that suspends rotations for one endpoint
  • Repair my personal items encryption keys, in My Profile, for an owner whose internal reference key went missing

Improved

  • The background key repair task now covers personal items, writing a key for their owner only
  • Personal folders are excluded from key redistribution by their position in the tree, instead of a flag that legacy data never set
  • An empty custom field is no longer reported as unreadable, and can be cleared again
  • The One-Time View page decodes stored entities, so descriptions and logins render as written
  • OAuth2 self-registration assigns the configured fallback role again
  • The Docker container applies every intermediate upgrade step and records the version reached
  • Published Docker images report the real version instead of the branch name
  • Every Tools page query builds its table name from the configured prefix, restoring two repair tools on installations that do not use the default one
  • Search no longer hides items sitting deep inside a personal folder
  • A password changed through the API is recorded in the item history
  • Item revision timestamps are returned wherever the revision is

Upgrade notes

  • Schema change — the upgrade wizard runs on every installation
  • Periodic LAPR endpoint checks stay off after an upgrade, so no outbound SSH starts without an administrator enabling it
  • Updating an item password through the API can now be refused while encryption keys are still being distributed — retry, the message says so
  • The web workflow that deleted unknown files is gone, replaced by the read-only report
  • Back up the database before upgrading

3.2.2.0

23 August 2026

LAPR — agentless rotation of Linux account passwords over SSH — plus item revisions for offline synchronization and three new notification types.

New

  • LAPR (Linux Account Password Rotation) — Teampass generates a password from a policy, pushes it to the server over SSH, then re-encrypts the item, so the vault only ever records a password the machine actually accepted
  • Agentless: nothing is installed on the target servers, and the existing item encryption model is reused rather than a parallel secret store
  • Managed endpoints with host key trust on first use, reusable rotation policies, and manual or scheduled rotation that retries then suspends instead of hammering an unreachable host
  • A dedicated audit log that never records a secret, and a separate "Can manage LAPR" permission held by non-administrators
  • Item revisions and a delta endpoint for offline clients, with an optional precondition on update that rejects a conflicting write instead of overwriting it
  • Notifications for local password expiry, knowledge base publication and backup failures
  • Versioned Docker image tags — teampass/teampass:3.2.2.0 can now be pinned

Improved

  • Search results open in a modal, with copy login and copy password directly on the row
  • A page transition indicator covering navigation and slow AJAX, replacing the Pace plugin
  • Browser-native confirmation dialogs replaced by the Teampass modal
  • Personal folders no longer listed in the role, folder and user management screens
  • Independent manual overrides for each web-server log path

Upgrade notes

  • Schema change — the upgrade wizard runs on every installation
  • LAPR is disabled by default, does nothing until an administrator enables it, and needs its own permission that no existing user receives on upgrade
  • Back up the database before upgrading

Full release notes on GitHub

Get the latest release

Upgrade instructions and a fresh install both live in the documentation.