Description
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Published: 2026-09-17
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been fixed by the SMAP team in the latest version of the app.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Title Weak password recovery mechanism for forgotten password in MobiAPParc
First Time appeared Mobiapparc
Mobiapparc mobiapparc
Weaknesses CWE-640
CPEs cpe:2.3:a:mobiapparc:mobiapparc:*:*:*:*:*:*:*:*
Vendors & Products Mobiapparc
Mobiapparc mobiapparc
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mobiapparc Mobiapparc
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-17T13:26:26.526Z

Reserved: 2026-07-06T11:42:50.483Z

Link: CVE-2026-14850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T14:17:12.117

Modified: 2026-09-17T14:17:12.117

Link: CVE-2026-14850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password