Keepassxc · Keepassxc · CVE-2023-35866
**Name of the Vulnerable Software and Affected Versions**
KeePassXC versions 2.7.5 and earlier
**Description**
A local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. The vendor's position is that asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker.
**Recommendations**
For KeePassXC versions 2.7.5 and earlier, as a temporary workaround, consider restricting access to the Database security settings until a patch is available. Avoid making changes to the master password and second-factor authentication without proper authentication.