This huge password manager exploit may never get fixed

It’s been a bad few months for password managers — albeit mostly just for LastPass. But after the revelations that LastPass had suffered a major breach, attention is now turning to open-source manager KeePass.

Accusations have been flying that a new vulnerability allows hackers to surreptitiously steal a user’s entire password database in unencrypted plaintext. That’s an incredibly serious claim, but KeePass’s developers are disputing it.

A large monitor displaying a security hacking breach warning.
Stock Depot/Getty Images

KeePass is an open-source password manager that stores its contents on a user’s device, rather than in the cloud like rival offerings. Like many other apps, however, its password vault can be protected with a master password.

The vulnerability, logged as CVE-2023-24055, is available to anyone with write access to a user’s system. Once that’s been obtained, a threat actor can add commands to KeePass’s XML configuration file that automatically export the app’s database — including all usernames and passwords — into an unencrypted plaintext file.

Thanks to the changes made to the XML file, the process is all done automatically in the background, so users are not alerted that their database has been exported. The threat actor can then extract the exported database to a computer or server they control.

It won’t be fixed

A depiction of a hacker breaking into a system via the use of code.
Getty Images

However, the developers of KeePass have disputed the classification of the process as a vulnerability, since anyone who has write access to a device can get their hands on the password database using different (sometimes simpler) methods.

In other words, once someone has access to your device, this kind of XML exploit is unnecessary. Attackers could install a keylogger to get the master password, for instance. The line of reasoning is that worrying about this kind of attack is like shutting the door after the horse has bolted. If an attacker has access to your computer, fixing the XML exploit won’t help.

The solution, the developers argue, is “keeping the environment secure (by using an anti-virus software, a firewall, not opening unknown e-mail attachments, etc.). KeePass cannot magically run securely in an insecure environment.”

What can you do?

password manager lifestyle image

While KeePass’s developers appear unwilling to fix the issue, there are steps you can take yourself. The best thing to do is to create an enforced configuration file. This will take precedence over other config files, mitigating any malicious changes made by outside forces (such as that used in the database export vulnerability).

You’ll also need to make sure regular users do not have write access to any important files or folders contained within the KeePass directory, and that both the KeePass .exe file and the enforced configuration file are in the same folder.

And if you don’t feel comfortable continuing to use KeePass, there are plenty of other options. Try switching to one of the best password managers to keep your logins and credit card details safer than ever.

While this is undoubtedly more bad news for the world of password managers, these apps are still worth using. They can help you create strong, unique passwords that are encrypted on all your devices. That’s far safer than using “123456” for every account.

Today’s tech news, curated and condensed for your inbox



Check your inbox!

Please provide a valid email address to continue.

This email address is currently on file. If you are not receiving newsletters, please check your spam folder.

Sorry, an error occurred during subscription. Please try again later.

Editors’ Recommendations








Read More
Alex Blake

Latest

Bungie Laying Off ‘Most of the Destiny Team and Some Marathon Team’

by William D'Angelo , posted 18 hours ago / 1,392 Views Sony Interactive Entertainment Studio Business Group CEO Hermen Hulst has announced PlayStation is laying off employees at Bungie. This includes "most of the Destiny team and some Marathon team members." Sony Interactive Entertainment teams that also support Bungie's operations have been hit with layoffs.

PlayStation CEO Says Goal for Cheaper Japan-Only PS5 Was Done to Revitalize Japanese Market

by William D'Angelo , posted 20 hours ago / 1,465 Views The President and CEO of Sony Interactive Entertainment (SIE) Hideaki Nishino in an interview with Famitsu said selling the cheaper Japan-only PlayStation 5 is being done to revitalize the PlayStation business in the country.  He also stated that due to the exchange rates caused

Josh Hokit reveals 7-figure sum he expects to have earned in the UFC by the end of 2026

It has been a controversial year for Josh Hokit — but also a lucrative one. The former American football player has become the latest fighter looking to gain prominence in the UFC with a polarizing persona. It looks to have worked for ‘The Incredible Hok’ so far, as he has already broken into the top

Detroit Lions Star football player facing LIFE in prison for Kidnapping Charges in Florida

Detroit Lions Star football player facing LIFE in prison for Kidnapping Charges in Florida Detroit Lions cornerback Terrion Arnold was arrested June 24 in Tampa, Florida, on four counts of kidnapping and four counts of armed robbery. Prosecutors allege Arnold coordinated the robbery and assault of his personal driver and two associates after accusing the

Newsletter

Don't miss

Bungie Laying Off ‘Most of the Destiny Team and Some Marathon Team’

by William D'Angelo , posted 18 hours ago / 1,392 Views Sony Interactive Entertainment Studio Business Group CEO Hermen Hulst has announced PlayStation is laying off employees at Bungie. This includes "most of the Destiny team and some Marathon team members." Sony Interactive Entertainment teams that also support Bungie's operations have been hit with layoffs.

PlayStation CEO Says Goal for Cheaper Japan-Only PS5 Was Done to Revitalize Japanese Market

by William D'Angelo , posted 20 hours ago / 1,465 Views The President and CEO of Sony Interactive Entertainment (SIE) Hideaki Nishino in an interview with Famitsu said selling the cheaper Japan-only PlayStation 5 is being done to revitalize the PlayStation business in the country.  He also stated that due to the exchange rates caused

Josh Hokit reveals 7-figure sum he expects to have earned in the UFC by the end of 2026

It has been a controversial year for Josh Hokit — but also a lucrative one. The former American football player has become the latest fighter looking to gain prominence in the UFC with a polarizing persona. It looks to have worked for ‘The Incredible Hok’ so far, as he has already broken into the top

Detroit Lions Star football player facing LIFE in prison for Kidnapping Charges in Florida

Detroit Lions Star football player facing LIFE in prison for Kidnapping Charges in Florida Detroit Lions cornerback Terrion Arnold was arrested June 24 in Tampa, Florida, on four counts of kidnapping and four counts of armed robbery. Prosecutors allege Arnold coordinated the robbery and assault of his personal driver and two associates after accusing the

NCAA New Eligibility Rules and When To Get Concerned with Alabama Recruiting on The Joe Gaither Show

Let's fire up a Wednesday edition of "The Joe Gaither Show on BamaCentral" as we welcome Theo Fernandez back to the program. We discuss the NCAA's new eligibility rules, Labaron Philon getting drafted and Alabama football recruiting. The show begins with the NCAA's new rules on eligibility. Will the 5-in-5 rule be an effective way to get

Business Insurance-AZ Achieves Record Response Times for 2026 Arizona Construction Bids

Business Insurance-AZ achieves milestone response speeds for commercial construction bids across Arizona, accelerating documentation delivery to keep local projects moving forward without delay. Phoenix, AZ, June 06-2026, ZEX PR WIRE — Business Insurance-AZ has achieved record-breaking processing speeds and response times for commercial construction bids throughout Arizona, directly supporting the state’s massive infrastructure and advanced manufacturing boom

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot