Description
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Password Reset
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the password reset functionality of MobiAPParc, where an attacker can modify the numeric user_id parameter that identifies the account. By changing this predictable identifier, an attacker can reset the password of any user without evidence of ownership, leading to unauthorized account access and potential data compromise.

Affected Systems

Affected systems are installations of the MobiAPParc application. The CNA lists only MobiAPParc itself; specific version information is not provided, but the issue exists until the latest release that incorporates the fix. All users of older releases could be impacted.

Risk and Exploitability

The CVSS base score of 8.8 signals high severity, and although EPSS data is not available, the lack of a KEV listing does not diminish the risk. Attackers can exploit the flaw remotely via the web interface, submitting forged requests with altered user_id values. Once a password is reset, the attacker gains full control of the victim's account, compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on September 17, 2026 at 21:46 UTC.

Remediation

Vendor Solution

The vulnerability has been fixed by the SMAP team in the latest version of the app.


OpenCVE Recommended Actions

  • Deploy the latest released version of MobiAPParc that includes the SMAP team fix.
  • Ensure that the password reset endpoint validates the user_id against the session or requires a confirmation token tied to the user.
  • Implement multi‑factor authentication for password reset flows or enforce account‑ownership verification (e.g., email or phone confirmation).

Generated by OpenCVE AI on September 17, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Title Weak password recovery mechanism for forgotten password in MobiAPParc
First Time appeared Mobiapparc
Mobiapparc mobiapparc
Weaknesses CWE-640
CPEs cpe:2.3:a:mobiapparc:mobiapparc:*:*:*:*:*:*:*:*
Vendors & Products Mobiapparc
Mobiapparc mobiapparc
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mobiapparc Mobiapparc
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-17T18:10:03.923Z

Reserved: 2026-07-06T11:42:50.483Z

Link: CVE-2026-14850

cve-icon Vulnrichment

Updated: 2026-09-17T18:09:57.489Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:12.117

Modified: 2026-09-18T19:21:49.497

Link: CVE-2026-14850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:00:16Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password