---
id: CVE-2026-14850
title: >-
  The password reset funcionality is vulnerable to unauthorized account
  modification due to improper validation of the user_id parameter
summary: >-
  The password reset funcionality is vulnerable to unauthorized account
  modification due to improper validation of the user_id parameter. An attacker
  can manipulate this predictable numeric identifier to reset passwords for
  arbitrary users…
severity: high
cvss: 8.8
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-640
vendor: MobiAPParc
product: MobiAPParc
affected:
  - MobiAPParc <= 2.28
  - MobiAPParc <= 2.42
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:21:49.497'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14850'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-forgotten-password-mobiapparc
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
epss: 0.00295
epssPercentile: 0.22402
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T18:09:52.488052Z'
cvssSource: cna
ingestedAt: '2026-09-17T14:19:30.967Z'
---

## Overview

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
