{"id":"CVE-2026-14850","title":"The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter","summary":"The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…","severity":"high","cvss":8.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-640"],"vendor":"MobiAPParc","product":"MobiAPParc","affected":["MobiAPParc <= 2.28","MobiAPParc <= 2.42"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:21:49.497","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14850","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-forgotten-password-mobiapparc","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"epss":0.00295,"epssPercentile":0.22349,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-17T18:09:52.488052Z"},"cvssSource":"cna","ingestedAt":"2026-09-17T14:19:30.967Z","slug":"CVE-2026-14850","body":"## Overview\n\nThe password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}