The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by the SMAP team in the latest version of the app.


Workaround

No workaround given by the vendor.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
Title Weak password recovery mechanism for forgotten password in MobiAPParc
First Time appeared Mobiapparc
Mobiapparc mobiapparc
Weaknesses CWE-640
CPEs cpe:2.3:a:mobiapparc:mobiapparc:*:*:*:*:*:*:*:*
Vendors & Products Mobiapparc
Mobiapparc mobiapparc
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-17T18:10:03.923Z

Reserved: 2026-07-06T11:42:50.483Z

Link: CVE-2026-14850

cve-icon Vulnrichment

Updated: 2026-09-17T18:09:57.489Z

cve-icon NVD

Status : Received

Published: 2026-09-17T14:17:12.117

Modified: 2026-09-17T19:16:37.523

Link: CVE-2026-14850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses